Dominik
Rimpel
"Three years running detections, investigations, and incident response in a 24/7 SOC. I trace things back to the file path, not just the dashboard."
Perimeter // active
Experience
0+ yrs
Certifications
0 active
Analysts Mentored
0+ / sem
Coverage
24 / 7
What I actually spend my time on.
Threat Detection
Writing and tuning detections across SIEM and NDR workflows to cut false positives and sharpen visibility.
Incident Response
Classifying, prioritizing, documenting, and escalating alerts in high-availability, mission-critical environments.
Threat Hunting
Using KQL, SPL, and enriched threat intelligence to chase anomalies before they become incidents.
>
status:
Method
Every case runs through the same six questions: who, what, where, when, why, how. It's less like solving one problem and more like a chain of puzzles, where finding one answer is what lets you find the next one.
- KQL
- SPL
- Sentinel
- Defender
- Carbon Black
- ExtraHop
- ServiceNow