Tomás Ferraz

7+ years in the SOC trenches, staring at alerts so you don’t have to.

– A mix of malware analysis, DFIR, detection engineering, malware development, and purple teaming—I (try to) write the malware, hunt the malware, and write the alerts to catch it.

– I firmly believe the best defense is offense: you can’t properly protect a network until you know how attackers build tools to burn it down.

– Off the keyboard, I like to run—far, far away, mostly to outpace the trauma of my last incident response.