Analyst

Hogan, Andre W.

Cybersecurity Analyst: Threat Hunting & Detection Engineering

Clearance
TS/SCIActive DoD, CI polygraph
Service
6 yrsU.S. Navy CWT, 2019–2026
Station
Pensacola, FLU.S. citizen, remote capable

Contact

Open to threat hunting, detection engineering and DCO roles

Plan view: service track

Six years hunting adversaries on DoD and mission-partner networks: Hunt Forward Operations and Cyber Protection Team work in direct support of the Cyber National Mission Force.

Packet, flow and protocol analysis by hand. Suricata, Sigma and YARA content written from what the hunt turned up. Analysts trained and qualified behind me.

Mission data

  • 14 TBpacket, flow and protocol data hunted
  • 98adversary TTPs run to ground
  • 35indicators of compromise, one Hunt Forward Op
  • 1,000+alerts triaged per mission cycle
Service track A plotted route from NIOC Hawaii at Wahiawa, through a second Wahiawa posting, to NIOC Pensacola, Florida in 2025. 2019 2023 2025 WAHIAWA, HI WAHIAWA, HI PENSACOLA, FL
Three duty stations, 2019 to 2026. The present fix is Pensacola.

Profile view: experience

  1. Feb 2025toJul 2026

    NIOC Pensacola, FL

    CWT2

    Cybersecurity Analyst / Senior Network Analyst

    • Led hypothesis-driven threat hunting across Security Onion, Elastic, Zeek, Suricata and full packet capture, targeting adversary behavior, lateral movement and gaps in security controls.
    • Ran 14 TB of packet, flow and protocol data against 98 adversary TTPs mapped to MITRE ATT&CK and the Cyber Kill Chain, and cleared every mission-partner network.
    • Triaged more than 1,000 alerts a mission cycle and walked junior analysts through correlation and root-cause work. What came out of it went back into the detection logic.
    • Surfaced roughly 300 vulnerabilities per mission, plus misconfigurations that only showed up in architecture and configuration review, then ranked the fixes by operational risk.
    • Pushed six vulnerabilities and one severe insecure-configuration practice straight to remediation after finding them mid-hunt across host and network telemetry.
    • Wrote and maintained Suricata, Sigma and YARA content. Sensor tuning against known TTPs widened ATT&CK coverage and cut false positives.
    • Built the work-role qualification pipeline and delivered 40 hours of JQR and operational training, qualifying three analysts across three work roles.
  2. Oct 2023toFeb 2025

    NIOC Hawaii / CNMF, Wahiawa, HI

    CWT2

    Cybersecurity Analyst / Crew Lead, Network

    • Lead network and protocol analyst on a Hunt Forward Operation: 35 indicators of compromise found across 2 TB of data and malicious activity confirmed, alongside commercial partners and two Cyber Protection Teams. Every mission objective was met.
    • Escalated confirmed intrusions with characterized adversary TTPs, enriched IOCs and containment recommendations. Mission-partner network owners validated and acted on all of them.
    • Senior analyst on intrusions across CNMF mission-partner networks: traffic analysis, IOC detection and enrichment, adversary TTP characterization.
    • Ran vulnerability discovery, network mapping and enumeration across several mission-partner environments, validating findings with local defenders before handing them off.
    • Built and ran adversary-emulation scenarios in Kali and Metasploit so analysts had live activity to detect against instead of canned data.
    • Designed a full-scope DCO cyber range to JQR work-role specification and directed three sailors through the build, shortening the qualification pipeline.
    • Trained 15 sailors on JQR requirements and mission tooling. Seven qualified, raising mission-ready analytic capacity 50%.
  3. Oct 2019toOct 2023

    NIOC Hawaii, Wahiawa, HI

    CTN3

    Cybersecurity Analyst / Host + Network Analyst

    • Found and mitigated network intrusions through hands-on traffic and protocol analysis. Qualified as Basic Host Analyst and Basic Network Analyst.
    • Worked host compromise on Windows and Linux: event and application logs, known-good image comparison for altered binaries, rogue accounts and elevated permissions via Sysinternals, PowerShell and native tooling.
    • Triaged suspected malware in isolated FLARE VM and REMnux builds, using snapshot comparison to catch what actually changed. The indicators went into detection content and mission reporting.
    • Reverse engineered suspicious binaries: PE structure and imports in CFF Explorer, embedded artifacts with strings, stepped execution in x64dbg to work out functionality, persistence and command-and-control behavior.
    • Imaged hosts with FTK Imager, examined them in Autopsy, recovered memory-resident artifacts with Volatility, and caught log tampering by reconciling local logs against forwarded copies.
    • Stood up range environments for six Cyber Protection Teams: 12 analyst workstations, the supporting server infrastructure, and 700 ft of fiber pulled and terminated. Training capacity up 400%.

Capability table

Tooling and methods used on mission, by category
CategoryUsed on mission
Network security monitoring Suricata · Zeek · Security Onion sensor tuning · Arkime · Wireshark and tshark · tcpdump · NetworkMiner · full packet capture · NetFlow and flow analysis · protocol analysis
SIEM and detection engineering Microsoft Sentinel (KQL) · Splunk (SPL) · Elastic and ELK (KQL, EQL, Lucene) · Sigma · YARA · use-case development · alert tuning and false-positive reduction · ATT&CK coverage mapping
Endpoint and forensics Defender for Endpoint and XDR · Cisco Secure Endpoint · Elastic Agent · Sysmon · Windows and Linux triage · baselining · Volatility · FTK Imager · Autopsy · timeline and anti-forensic analysis
Malware analysis Static and dynamic analysis · x64dbg and x32dbg · CFF Explorer · FLARE VM · REMnux · sandbox detonation with snapshot comparison · persistence and C2 identification · IOC extraction
Threat intelligence MITRE ATT&CK mapping · Cyber Kill Chain · Diamond Model · IOC development and enrichment · pivoting · adversary infrastructure tracking · actor profiling
Vulnerability and architecture ACAS (Nessus) · RedSeal exposure-path mapping · discovery and validation · firewall, router and switch configuration review · remediation prioritized by operational risk
Automation Python · PowerShell · BASH · Terraform · Ansible · Docker · Kubernetes · Git and CI/CD
Frameworks and identity NIST 800-53 · NIST CSF · RMF · CMMC · Zero Trust · Entra ID and on-premises Active Directory · AWS and Google Cloud · LAN, WAN, VPN, switching and routing

Notes

Clearance and certification

  • Active DoD TS/SCI with CI polygraph
  • DoD 8140/8570 IAT Level II in progress
  • CompTIA Security+ (SY0-701) in progress

Education

  • Western Governors University, B.S. Cybersecurity and Information Assurance in progress, expected 2027

Schools and qualifications

  • SANS FOR572: Advanced Network Forensics and Incident Response
  • Deloitte Advanced Cyber Training: Adversary Tactics and Techniques, 240 hrs
  • DC3 Cyber Training Academy: Discovery and Counter-Infiltration, 320 hrs
  • Joint Cyber Analysis Course (JCAC)
  • Intermediate Cyber Core (ICC)
  • Network Security Monitoring Operator Course
  • JCTE Certified Range Engineer, Advanced and Basic
  • Intermediate Leader Development Course, Naval Leadership and Ethics Center
  • Navy work roles: Senior Network Analyst, Basic Host Analyst, Basic Network Technician

Supplement: built off duty