Behavioral Analytics & Forensics
Surfacing hidden log relationships: Teams activity, endpoint attribution & badge reconciliation
Correlating fragmented telemetry across Microsoft Teams collaboration events, endpoint process trees, VPN concentrators, and physical badge swipes to reconstruct complex user behavior.
Investigation Outcomes
Resolved fragmented Azure AD, sensor IDs, and MAC addresses into an unbroken, single identity trail.
High-throughput pipeline correlating physical badge logs with digital collaboration events at scale.
Direct evidentiary telemetry strictly decoupled from investigative analytical hypothesis.
Objective, audit-ready event chronology formatted for immediate executive disposition.
The Challenge
The Collaboration Blind Spot
Collaboration platforms like Microsoft Teams create massive audit trails, but logs often lack direct physical endpoint identifiers or clear session context. Determining which exact corporate laptop, virtual desktop, or unmanaged mobile device initiated a sensitive file share was virtually impossible with standard queries.
Physical vs. Digital Disconnect
Physical building badge events existed in a separate database from corporate VPN and Active Directory authentication logs, preventing investigators from detecting concurrent sessions or physical/digital anomalies.
Engineering & Methodology
01. Device-to-Session Correlation Logic
Developed high-precision correlation algorithms linking Teams message and file-attachment timestamps with Azure AD sign-in logs, tenant device IDs, CrowdStrike sensor network sockets, and browser session cookies.
02. Physical-to-Digital Reconciliation
Automated the continuous ingestion and mapping of physical badge access events alongside VPN IPs, identifying impossible travel speeds, badge pass-backs, and off-hours facility access coupled with data staging.
What I Shipped
Unified User Reconstruction Pipeline
An automated data-pipeline that takes a subject identity and reconstructs an unbroken, cross-telemetry timeline of physical movements, login events, collaboration shares, process executions, and file movements.
Defensible Evidentiary Reporting
Engineered clean, objective timeline visualizers that clearly separate direct factual observations from investigative inferences, providing rock-solid evidence packages for Legal, HR, and Compliance teams.