🛡️ Modular Python framework for Cybersecurity LLM agents, purple team automation, log triage, and detection engineering in lab environments.
-
Updated
Aug 9, 2026 - Python
🛡️ Modular Python framework for Cybersecurity LLM agents, purple team automation, log triage, and detection engineering in lab environments.
A command-line tool for analysing Suricata EVE JSON alert logs and converts them to .txt readable output for SIEM analysis. Built with Python, 2026.
This project required the built-in of high-confidence detections in Microsoft Sentinel using KQL, focusing on identity security and reducing false positives. This project targets MFA bypass and correlates signals like impossible travel and abnormal access patterns to detect real-world attacks.
"A comprehensive network security lab featuring FortiGate NGFW configuration, firewall policy management, and real-time traffic monitoring and analysis."
Windows security investigation analyzing failed authentication attempts using Event Viewer and Event ID 4625.
IT Support and SOC portfolio project with practice scenarios, questions, and a React based SOC and IT simulator
Network traffic investigation using Wireshark to analyze HTTP traffic and identify network communication patterns.
Artefact conçu pour déplacer la surface d'action vers la représentation opérationnelle d'un système défensif. Pas d'exploitation, pas de persistance. L'espace cognitif comme terrain. Ce qui cesse d'être observé pendant la qualification est l'espace dans lequel il opère.
SOC-style phishing incident investigation analyzing a multi-vector job scam campaign. Performed email header analysis, URL inspection, and IOC extraction; mapped attack techniques to MITRE ATT&CK and documented findings with remediation and responsible disclosure.
Professional phishing email analysis report and employee security awareness framework for corporate risk mitigation.
Cybersecurity Engineering student passionate about technology, security, and continuous learning. Building practical projects, exploring emerging technologies, and developing skills to solve real-world challenges.
SOC alert investigations, SIEM practice labs, and incident analysis exercises completed on LetsDefend.
Network traffic investigation using Wireshark to analyze DNS, TCP, TLS and HTTP traffic.
SOC investigation and ransomware analysis project focused on WannaCry simulation, IOC collection, and MITRE ATT&CK mapping.
The technical analysis of a multi-stage phishing campaign targeting university infrastructure.
Enterprise security homelab simulating Active Directory, SIEM operations, threat detection, and internal attack scenarios in a virtualised on-prem environment.
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.
Investigated suspicious Microsoft 365 sign in activity using portal triage, containment actions like session revocation and stronger authentication, then validated remediation and practiced structured KQL hunting patterns with Azure Monitor Logs demo data.
AI-assisted SOC triage pipeline - real AD attack alerts fed through Claude API for automated Tier 1 analysis. Includes analyst dashboard, AI vs manual comparison, and documented hallucination found during failure testing.
This repository is a structured, research-driven documentation of my journey...
Add a description, image, and links to the soc-analysis topic page so that developers can more easily learn about it.
To associate your repository with the soc-analysis topic, visit your repo's landing page and select "manage topics."