
AtriCure
IT security and infrastructure co-op, Mason, OH · –
Built the pipeline that surfaced a dangling DNS record, and worked the phishing, shadow IT and identity queues at a medical device company.
I spent the summer on the IT security and infrastructure team, splitting time between the daily queues and building things that made the queues smaller. The daily work was phishing triage across the company’s monitored mailboxes and shadow IT review in Defender for Cloud Apps. The build work was a Cloudflare-to-Sentinel ingestion pipeline, a KnowBe4 analytics dashboard for leadership, and an SSO audit across every Entra-integrated application.
Two of those turned into writeups: catching a dangling DNS record with a Cloudflare-to-Sentinel pipeline and hunting shadow IT with Defender for Cloud Apps.
- Uncovered a dangling DNS record exposing the production environment to subdomain takeover, by building an Azure Function App that ingests 51 Cloudflare security insight classes into Microsoft Sentinel through a webhook and a custom data collection rule.
- Reduced phishing investigation turnaround by about 35% across 200+ monitored mailboxes by triaging and dispositioning suspicious email daily with Microsoft Defender XDR Threat Explorer, ANY.RUN, and VirusTotal.
- Built a KnowBe4 phishing simulation analytics dashboard covering 40+ departments, presented to VP leadership and escalated to the executive leadership team.
- Identified and blocked a cloud storage application posing a data exfiltration risk by auditing 200+ unsanctioned cloud apps with Microsoft Defender for Cloud Apps and McasShadowItReporting KQL queries.
- Audited SSO configuration and authentication protocols (SAML and OIDC) across 335 Entra-integrated cloud applications, finding 4 apps with expired SAML certificates and 8 operating without SSO.