01
ML for Threat Detection
My core focus. Building intrusion-detection models that map alerts to MITRE ATT&CK, anomaly classifiers on imbalanced data, phishing analysers that catch what email gateways miss. Most cyber analysts cannot build a model; most ML engineers do not know what ATT&CK is. I sit in the middle.
- scikit-learn
- PyTorch
- XGBoost
- MITRE ATT&CK