Incident response · phishing investigation · endpoint security

Trenton Van Orden

Cybersecurity Professional | Security+ & CySA+

Hands-on security operator with experience investigating and remediating 1,000+ security incidents and 300+ phishing cases. I work daily in Microsoft Defender XDR, SentinelOne, CrowdStrike, Huntress, Entra ID, Intune, Microsoft 365, and Google Workspace.

  • Defender XDR
  • SentinelOne
  • CrowdStrike
  • Huntress
  • Entra ID
  • Intune
1,000+Security incidents investigated
300+Phishing incidents handled
2,000+Support tickets resolved
95%Customer satisfaction rating

Focus areas

Built for security operations

Incident response

Triage and containment across endpoint and identity alerts using Defender XDR, SentinelOne, CrowdStrike Falcon, RocketCyber, and Huntress.

Phishing investigation

Investigate compromised accounts and suspicious authentication using Entra ID and Google Workspace audit logs, then close the loop with the user.

Endpoint & identity

Administer Entra ID, Intune, Microsoft 365, and Google Workspace while supporting Windows, macOS, Linux, and mobile endpoints.

Log pipeline

Generate, balance, filter, route

How telemetry from endpoints, identity, email, and the firewall is ingested, load balanced, and sent to the right place.

Security log pipeline Logs from endpoint, Entra ID, mail, and firewall go through ingest, a load balancer, parse or enrich or drop, then route to SIEM, IR queue, or archive. ENDPOINT ENTRA ID MAIL FIREWALL INGEST LB load balance PARSE ENRICH DROP ROUTE SIEM / XDR IR QUEUE ARCHIVE
Logs are generated at the source, load balanced, parsed or dropped, then routed to hunt, contain, or retain.