Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
-
Updated
Apr 13, 2026
Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your attack surface over time, and gate your CI/CD — all free.
ShadowWall AI is a cutting-edge, enterprise-grade cybersecurity platform that employs artificial intelligence, machine learning, and advanced deception techniques to provide comprehensive protection against sophisticated cyber threats. Designed for security professionals, SOC teams, and organizations requiring proactive threat defense.
A lightweight SOC-focused threat intelligence platform built with Python & Flask. Manage, search, and export IOCs (IPs, domains, file hashes) with live AbuseIPDB enrichment and an interactive dashboard.
Sigma-format SAST detection rules for Active Directory attack techniques — CLAUDE 94 rules across 14 categories, mapped to MITRE ATT&CK v14 | For blue teams, SOC analysts and purple team exercises
Wazuh SIEM SOC Analyst Training Manual WITH THINGS A NEWBIE MUST KNOW BEFORE USING THE WAZUH.
Global Enterprise Threat Intelligence & Incident Response Platform. Autonomous AI Security Analyst, Zero-Key VirusTotal/Shodan/AbuseIPDB Engines, SIEM Log Triage, Interactive Analyst Shell, EDR Telemetry & MITRE ATT&CK Visual Heatmaps.
This portfolio focuses on my abilities how to deal with Tryhackme challenges / labs, which contain a full bunch of important programs and frameworks used in real life scenarios.
Automated Python script that parses Linux auth logs to detect SSH brute force attacks and generate incident reports
Hey 👋, This Lab was made by Riad Moudjahed, a friendly malware analysis lab. "README" contains everything you need.
Python tool that parses firewall logs and auto-detects port scans, brute-force attempts, and anomalous IPs — with charts and an HTML report generated automatically.
Performed Tier 1 SOC incident triage in Splunk Enterprise by analyzing Windows Security Event Logs and applying the Who, What, When, Where, and How methodology to investigate and assess security events.
Automated job search engine for remote, entry-level roles in cybersecurity, IT support, SOC analysis, and data labeling, scrapes 10+ job boards, filters by seniority and location eligibility, scores listings, and generates AI-tailored resumes via a local dashboard
Python-based automated incident response framework ( Phishing analysis, Threat intel enrichment, IR playbooks, Vulnerability reporting, and NIST CSF compliance tracking.)
Documentation of my 3-month Cyberster Blue Team internship — covering SOC operations, SIEM lab setup (VirtualBox, Wazuh), network traffic analysis, detection rules, and incident response, building toward a Blue Team / SOC Analyst role."
A comprehensive technical audit and penetration testing lab focused on SSH exploitation, MITRE ATT&CK mapping, and Linux forensic log analysis.
A hands-on SOC/XDR laboratory built using Wazuh, Ubuntu, Windows, and Sysmon. The project covers Wazuh SIEM deployment, Windows agent enrollment, Windows Event Log monitoring, Sysmon integration, Security Configuration Assessment (SCA), endpoint monitoring, detection engineering, threat hunting, and incident response. Future phases include vuln
Credentialed Nessus vulnerability assessment on a Windows 11 VM, with evidence screenshots, severity analysis, Graylog dashboard visualization, and a remediation plan. Demonstrates the full vulnerability management lifecycle from discovery to prioritization.
DexSentinel is a high-performance, real-time threat intelligence aggregator designed to provide global visibility into attack surface pressure. It correlates live telemetry with public OSINT feeds to offer a unified dashboard for security researchers and SOC analysts.
Add a description, image, and links to the socanalyst topic page so that developers can more easily learn about it.
To associate your repository with the socanalyst topic, visit your repo's landing page and select "manage topics."