Skip to content
View jhunte-sec's full-sized avatar

Block or report jhunte-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jhunte-sec/README.md
Jason Hunte: blue team and detection engineering. Security student at Seneca Polytechnic, Ontario, Canada.

I build detections, tune them until they're quiet, and write up what they catch. Aiming at SOC and blue team roles. Best way to reach me: LinkedIn.

Featured: beacon-hunter

Finds malware "phoning home" in network logs, explains every finding in plain English, and writes a one-file report you can attach to a ticket. Reads Zeek, Suricata, Sysmon, CSV exports and raw packet captures.

beacon-hunter report on a real malware capture: 2 pairs worth a look, and a beacon map where the malware's two command servers stand out as solid timers 0.35 to 1.00 on Mirai botnet's real command channel; 9 of 9 conversations rebuilt from raw packets match Zeek's own log; 0 of 1,500 false alarms on simulated non-beacon traffic

The write-up covers what it misses, and a mistake I caught and corrected along the way.

My detection lab

Lab architecture: an outside attacker VM, a router and firewall between seven zones (DMZ edge, App, Internal, SOC, User, Admin, Remote), network taps from the SOC's IDS into the DMZ, App and Internal zones, and Wazuh agents on every host

Built for a network security course at Seneca. Attacks come only from outside, through the DMZ, and every one has to show up as a specific alert someone can act on.

Detections tuned in Wazuh, Zeek and Suricata so each attack raises one specific alert; a triage queue and a weekly threat hunt; domain controllers taken from 28% to 92% on the CIS Level 1 benchmark, plus AppLocker and a three-tier PKI

The lab itself stays private (it's coursework and holds credentials), but I'm glad to demo it or walk through any rule.

Also

Incident response and forensics coursework: evidence collection, triage, and client-ready findings. SOC-in-a-box, in progress: drop in a packet capture or Windows logs and get a full incident case report

Tools I use

Detection and monitoring: Wazuh, Zeek, Suricata, Sysmon. Windows and identity: Active Directory, Group Policy, PKI. Code: Python, Bash, PowerShell. Lab: VMware, Windows Server, Ubuntu, WireGuard Open to junior SOC and blue team roles. Connect on LinkedIn

Pinned Loading

  1. beacon-hunter beacon-hunter Public

    Find C2 beaconing in Zeek, Suricata, Sysmon, CSV and pcap logs. Catches beacons that miss check-ins or call dead servers, explains every finding, and writes a one-file HTML report. Evaluated on IoT…

    Python