Detection Rules
One detection library. Nine security platforms. No single-platform gaps.
Open to security engineering opportunities
I'm Wahid Hendrawan, a security engineer and product builder focused on detection engineering, threat hunting, DFIR, threat intelligence, vulnerability management, and secure infrastructure.
Indonesia - Working globally
Selected work
From portable detection content to threat hunting workspaces and investigation platforms, each project is designed to reduce friction for security teams.
One detection library. Nine security platforms. No single-platform gaps.
A centralized platform for operational threat intelligence, hunting context, and security workflows.
Investigation tooling that brings evidence, triage, and response into one workspace.
Translate malware intelligence into portable SIEM and EDR detections.
Capabilities
I work across the path from raw evidence and threat behavior to usable tooling, durable detection, hunting workflows, and secure delivery.
Sigma authoring, cross-platform translations, ATT&CK coverage, rule quality, and detection lifecycle thinking.
Hypothesis-driven hunts, IOC enrichment, ATT&CK mapping, evidence pivots, and analyst workflows for finding hidden threats.
Log, network, and memory triage; evidence correlation; incident playbooks; and analyst-focused investigation tooling.
Purpose-built dashboards and operational systems for vulnerability, intelligence, hunting, and SOC workflows.
Containerized delivery, multi-IaC workflows, system hardening, and security-conscious automation.
About
My work sits at the intersection of security operations and software engineering. I turn recurring analyst problems into focused products, automation, and reusable open-source knowledge.
The common thread is practical impact: clearer evidence, stronger detection coverage, sharper threat hunting, faster investigation, and infrastructure that is easier to reason about.