Joseph Daniel
Purple Team Security Engineer focused on adversary emulation, detection engineering, incident response, security operations and Azure cloud security.
Engineering security across offense and defense.
My work is centered on understanding how adversary behavior appears inside real systems and using that understanding to improve defensive visibility, investigation and resilience.
Rather than treating offensive testing, security monitoring and incident response as separate activities, I approach them as a continuous validation cycle:
The objective is not simply to demonstrate that an attack technique works. The objective is to determine whether it was visible, whether it could be detected, whether it could be investigated and whether the defensive improvement survives retesting.
Joseph Daniel & BELISARIUS13
The professional identity and technical brand have different purposes, but they represent the same body of work.
Joseph Daniel
My public professional identity for cybersecurity engineering, professional networking and career development.
BELISARIUS13
My technical security lab for documenting reproducible campaigns, detections, investigations, cloud-security experiments and research.
B13
The visual shorthand used across lab telemetry, campaign identifiers, technical artwork and the BELISARIUS13 interface.
Security engineering focus
The portfolio is deliberately concentrated around capabilities that support Purple Team engineering.
Adversary Emulation
Controlled ATT&CK-aligned activity used to test telemetry, detections and security controls.
Detection Engineering
Turning observed behavior into testable detection hypotheses, queries and validated defensive logic.
Incident Response & DFIR
Evidence collection, investigation, timeline reconstruction, root-cause analysis and remediation validation.
Threat Hunting
Using endpoint, network and cloud telemetry to search for behavior that may not yet generate an alert.
Azure Security
Identity, workload, posture, policy, logging and cloud-security control validation.
Security Automation
Using scripting, version control and repeatable workflows to improve security engineering efficiency.
Adapt. Observe. Reposition.
The technical brand takes inspiration from strategic adaptability: understanding the environment, adjusting to changing conditions and using both offensive and defensive capability effectively.
A security lab built around adaptation
BELISARIUS13 represents the idea that security engineering is not a static configuration exercise. Attack techniques change, telemetry changes, infrastructure changes and detections degrade over time.
The lab therefore emphasizes continuous validation: generate activity, measure the defensive response, improve the environment and test again.
The evidence is in the campaigns.
The portfolio is designed so claims about technical capability are supported by reproducible projects, detections and research.