B13 // OPERATOR PROFILE

Joseph Daniel

Purple Team Security Engineer focused on adversary emulation, detection engineering, incident response, security operations and Azure cloud security.

PURPLE TEAM DETECTION ENGINEERING DFIR THREAT HUNTING AZURE SECURITY SECURITY OPERATIONS
Joseph Daniel - Purple Team Security Engineer
OPERATOR JOSEPH DANIEL ROLE PURPLE TEAM SECURITY ENGINEER
PROFESSIONAL IDENTITY

Engineering security across offense and defense.

My work is centered on understanding how adversary behavior appears inside real systems and using that understanding to improve defensive visibility, investigation and resilience.

Rather than treating offensive testing, security monitoring and incident response as separate activities, I approach them as a continuous validation cycle:

ATTACK → OBSERVE → DETECT → INVESTIGATE → CONTAIN → HARDEN → RETEST

The objective is not simply to demonstrate that an attack technique works. The objective is to determine whether it was visible, whether it could be detected, whether it could be investigated and whether the defensive improvement survives retesting.

IDENTITY MODEL

Joseph Daniel & BELISARIUS13

The professional identity and technical brand have different purposes, but they represent the same body of work.

01 // PROFESSIONAL

Joseph Daniel

My public professional identity for cybersecurity engineering, professional networking and career development.

02 // TECHNICAL

BELISARIUS13

My technical security lab for documenting reproducible campaigns, detections, investigations, cloud-security experiments and research.

03 // INSIGNIA

B13

The visual shorthand used across lab telemetry, campaign identifiers, technical artwork and the BELISARIUS13 interface.

CORE PRACTICE

Security engineering focus

The portfolio is deliberately concentrated around capabilities that support Purple Team engineering.

01

Adversary Emulation

Controlled ATT&CK-aligned activity used to test telemetry, detections and security controls.

02

Detection Engineering

Turning observed behavior into testable detection hypotheses, queries and validated defensive logic.

03

Incident Response & DFIR

Evidence collection, investigation, timeline reconstruction, root-cause analysis and remediation validation.

04

Threat Hunting

Using endpoint, network and cloud telemetry to search for behavior that may not yet generate an alert.

05

Azure Security

Identity, workload, posture, policy, logging and cloud-security control validation.

06

Security Automation

Using scripting, version control and repeatable workflows to improve security engineering efficiency.

WHY BELISARIUS

Adapt. Observe. Reposition.

The technical brand takes inspiration from strategic adaptability: understanding the environment, adjusting to changing conditions and using both offensive and defensive capability effectively.

B13

A security lab built around adaptation

BELISARIUS13 represents the idea that security engineering is not a static configuration exercise. Attack techniques change, telemetry changes, infrastructure changes and detections degrade over time.

The lab therefore emphasizes continuous validation: generate activity, measure the defensive response, improve the environment and test again.

JOSEPH DANIEL // BELISARIUS13 Offense informs defense. Detection drives improvement.