Nathan Gomes Ferreira

4+ Years Experience
7 Certifications

With this blog, I want to share a part of the work I do on my spare time exploring security operations, detection engineering, and threat research.

I've learned a lot from the infosec community and my objective is to give back however I can. I'm not an expert - just someone who enjoys learning and sharing the journey.

Expertise

Detection Engineering

Designing high-fidelity detection rules aligned with MITRE ATT&CK. Behavioral analytics, correlation queries, and false positive reduction.

Threat Hunting

Proactive threat hunting using EDR telemetry and SIEM data. Identifying IOCs, lateral movement, and advanced persistent threats.

SIEM Administration

End-to-end SIEM deployment and administration. CrowdStrike LogScale, Splunk, Elastic, Microsoft Sentinel, and Google Chronicle.

Offensive Research

Understanding adversary tradecraft to build better defenses. Red team tactics, adversarial ML, and attack simulation.

Certifications

CrowdStrike SIEM Engineer

CCSE January 2026

CompTIA Security+

SY0-701 2025

CrowdStrike Falcon Responder

CCFR 2025

Network Security Practitioner

CNSP 2025

CyberSecurity Analyst

C3SA 2025

Red Team Analyst

CRTA 2025

Network Essentials

Cisco 2022
In Progress:
CySA+ (CS0-003) CEH (EC-Council)

Technical Skills

SIEM & EDR

CrowdStrike Falcon LogScale / NG-SIEM Splunk Elastic SIEM Microsoft Sentinel Google Chronicle Cortex XDR

Security Operations

Incident Response Threat Hunting Detection Engineering Alert Triage SOAR Playbook Development

Frameworks

MITRE ATT&CK NIST CSF Kill Chain

Technical

PowerShell Bash Python KQL SPL CQL

Education

2025 - 2026

Professional Specialization in Data Science

Unicamp (State University of Campinas)

Machine Learning, MLOps, Data Architecture - Applied to cybersecurity

2024 - 2026

Postgraduate in Offensive Cybersecurity

Acadi-TI
2020 - 2023

Associate in Information Technology

Estacio University

Speaking & Achievements

Featured Speaker

CrowdStrike Invited Speaker

"Next-Gen SIEM Use Cases" - Co-presented with CrowdStrike LATAM leadership on Falcon LogScale implementation, CQL query patterns, and ATT&CK-aligned detection strategies.

August 2025

Let's Connect

Interested in discussing security research, detection engineering, or collaboration opportunities?