Skip to content
View gustavo89587's full-sized avatar

Block or report gustavo89587

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
gustavo89587/README.md
πŸ‘¨β€πŸ’» Gustavo Okamoto

Detection Engineering β€’ Automation Governance β€’ Trust Modeling

Engineering trust in automated security systems.

Detection engineer operating at the intersection of:

Signal fidelity

Telemetry integrity

Automation boundaries

Degradation modeling

Sustainable SOC operations

My work focuses on one structural principle:

Security automation must be governed by explicit trust boundaries β€” not assumed confidence.

🧠 Founder β€” Detection Fidelity Score (DFS)

Creator and maintainer of Detection Fidelity Score (DFS) β€” a structured framework for:

Modeling detection degradation (Loss, Distortion, Drift)

Defining explicit Trust Decision Boundaries

Governing automation eligibility

Making detection debt visible

Aligning engineering rigor with executive accountability

DFS shifts the industry question from:

β€œDoes it detect?”

to

β€œIs this signal trustworthy enough to automate?”

πŸ”— Repository:

https://github.com/gustavo89587/detection-fidelity-score

πŸ”¬ Technical Foundation

Governance without engineering depth is theory. My foundation remains deeply technical:

Focused on:

Windows internals & Sysmon telemetry

Behavioral detection engineering

SIEM parsing & normalization reliability

Telemetry pipeline architecture

Signal-to-noise optimization

Automation risk containment

πŸš€ Open Source Contributions

Contributing to ecosystems used by blue teams in production environments.

πŸ›‘ SigmaHQ

Behavioral detection refinement

Context-aware rule logic

False-positive reduction without coverage loss

🧩 Wazuh

Windows & Sysmon decoder reliability

Telemetry normalization improvements

Downstream detection viability enhancements

πŸ“‘ OpenTelemetry Collector

Telemetry structuring for security analytics

Pipeline stability improvements

Bridging observability and detection engineering

🧭 Detection Philosophy

Detection is not about generating alerts.

It is about governing which signals deserve:

Human escalation

Automated response

Contextual enrichment

Trust degrades. Automation scales impact.

Without explicit modeling, it scales fragility.

πŸ“« Contact

GitHub: https://github.com/gustavo89587

Pinned Loading

  1. soc-incident-response-playbooks soc-incident-response-playbooks Public

  2. cloud-security-labs-aws cloud-security-labs-aws Public

    Python 1

  3. blue-team-detection-labs blue-team-detection-labs Public

  4. soc-threat-intel-automation soc-threat-intel-automation Public

    Python

  5. OKAMOTO-SECURITY-LABS-INCIDENT-RESPONSE-REPORT OKAMOTO-SECURITY-LABS-INCIDENT-RESPONSE-REPORT Public