Information Security Officer · Incident Response · MSP Security

Patrick WindjackSecurity operations for small orgs that can't afford a breach.

I'm the Information Security Officer at Hoola Technology, a managed IT provider in Indiana. I run incident response, endpoint triage and log forensics, and I harden the email, network and identity stacks for healthcare, local government and small businesses across many industries.

  • CompTIA CySA+
  • CompTIA Security+
  • CompTIA Network+
  • CompTIA A+

What I do

Hands-on security work across many client tenants, where each environment has its own compliance constraints.

Incident response

Triage, containment and root cause, from session-hijacking phishing and compromised mailboxes to command-and-control traffic on a client network.

Endpoint & EDR

Managed EDR layered with built-in OS protection. Investigating detections, isolating hosts and cleaning up persistence.

Email security

SPF, DKIM, DMARC and MTA-STS rollouts, email security gateway policy design, and vendor compromise triage.

Network & perimeter

Next-gen firewalls, business wireless, VPN and SASE. Access-rule audits and log analysis.

Identity & M365

Microsoft 365 identity, device management and mail hardening, conditional access, and tenant security reviews.

Automation

PowerShell and Microsoft Graph tooling for audits, sweeps and repeatable remediation across tenants.

Case files

Based on real engagements. Client names, industries, dates and identifying details are withheld or changed.

CASE-01CriticalSingle client

Finding the real patient zero in a session-hijacking compromise

My role
Lead investigator. Re-examined an automated first-pass report against the raw audit logs.
Signal
An AI-generated incident report named one user as the entry point and concluded that nothing had left the tenant.
Action
Rebuilt the timeline from raw sign-in, mail, file-sharing, OAuth and admin logs. The phishing lure came from a real, compromised vendor account, so it passed SPF, DKIM and DMARC. A different user clicked first and forwarded it internally. Within two minutes of the second click, the attacker replayed the stolen session through an adversary-in-the-middle relay, then hid the platform's security alerts, read contract and banking threads for about two weeks, and sent fraudulent replies on a live invoice thread before deleting the sent copies.
Result
A corrected report fixing nine errors in the original, with every claim checked programmatically against the logs. The targeted third party was warned before any payment went out, so no money was lost, and a follow-up sweep of every mailbox found no further compromise.
Takeaway
AI-assisted triage is fast, but its conclusions have to be verified against raw evidence before anyone acts on them.
  • T1557 Adversary-in-the-Middle
  • T1114.002 Remote Email Collection
  • T1070.008 Clear Mailbox Data
CASE-02HighMultiple clients

Rogue remote-access tools across client endpoints

My role
Led the audit end to end.
Signal
RMM monitoring surfaced remote-access agents nobody had approved, including leftover agents from older deployments.
Action
Built an approved-tools baseline, swept every tenant, and treated any off-list agent as an indicator of compromise until proven otherwise.
Result
A repeatable audit process, plus detection rules that flag unknown remote-support relays and unapproved remote-access agents.
  • T1219 Remote Access Tools
  • EDR
  • RMM monitoring
CASE-03HighSingle client

Payment fraud through a compromised vendor mailbox

My role
Lead investigator.
Signal
A trusted vendor's real mailbox sent altered payment instructions to a client.
Action
Traced the message chain, scoped which mailboxes were exposed, and tightened inbound rules and payment-change verification.
Result
Contained and documented, then turned into a reusable playbook for vendor email compromise.
  • T1566 Phishing
  • T1534 Internal Spearphishing
  • Email security
CASE-04CriticalSingle client

Investigating command-and-control beaconing on a client network

My role
Lead investigator and report author.
Signal
Firewall logs showed periodic outbound connections consistent with command-and-control.
Action
Correlated firewall and network logs to isolate the source devices, then contained them.
Result
Findings delivered as a written security assessment with remediation steps.
  • T1071.001 Web Protocols
  • Firewall forensics
  • Log correlation
CASE-05MediumSeveral domains

Stopping domain spoofing with staged DMARC

My role
Planned and ran each rollout.
Signal
Client domains were being spoofed in phishing sent to those clients' own customers.
Action
Inventoried every legitimate sender, fixed SPF and DKIM alignment, then moved DMARC from monitoring to enforcement and added MTA-STS.
Result
Spoofed mail rejected at the receiver, with no legitimate mail broken along the way.
  • T1656 Impersonation
  • DMARC
  • MTA-STS

Automation

Recurring work I used to do by hand, now automated with the help of an AI assistant. I still make the decisions; the automation does the legwork.

Scheduled · AI-assisted

Daily threat brief

Pulls the day's security news and vendor advisories, filters them to the platforms our clients actually run, and drops anything already patched or not deployed.

hoursminuteseach morning
Read-only connector · AI-assisted

Ticket triage

Reads a support ticket and its attached diagnostic report, then drafts a first assessment. Runs locally with read-only access, so it can't change anything in the ticketing system.

~10 minsecondsto an initial diagnostic
Scripted checks · AI-assisted

Incident log verification

Tests every claim in an incident report against the raw audit logs: timestamps, addresses, accounts, event counts, and negative claims like "no activity from this source." It's how the errors in CASE-01 were caught.

~1 hoursecondsto an initial diagnostic

Writing

Field notes from the MSP side of security. First posts in progress.

Toolbox

The categories I work in day to day. Specific products available on request.

Detect & respond

  • Managed EDR / MDR
  • Endpoint protection
  • Security awareness training
  • Credential exposure monitoring

Email

  • Email security gateway
  • Cloud mail platforms
  • DMARC reporting & monitoring
  • SPF · DKIM · DMARC · MTA-STS

Network

  • Next-gen firewalls
  • Business wireless
  • Site-to-site & remote-access VPN
  • SASE / zero-trust access

Platform & ops

  • Cloud identity & device management
  • RMM & PSA platforms
  • Remote support tooling
  • Backup & disaster recovery
  • PowerShell · Graph API

Let's talk security.

Happy to compare notes on incident response, email authentication or running security inside an MSP. The best way to reach me is a message on LinkedIn.