Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
-
Updated
Apr 13, 2026
Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
ShadowWall AI is a cutting-edge, enterprise-grade cybersecurity platform that employs artificial intelligence, machine learning, and advanced deception techniques to provide comprehensive protection against sophisticated cyber threats. Designed for security professionals, SOC teams, and organizations requiring proactive threat defense.
60+ detectors for web, plus mobile apps and smart contracts. Every finding is mapped to the OWASP Top 10, marked Confirmed when we have proof, and comes with AI fix guidance — plus scheduled scans, the Red vs Blue Arena, branded PDF reports and CI/CD gating. Free, open-source and self-hostable.
Sigma-format SAST detection rules for Active Directory attack techniques — CLAUDE 94 rules across 14 categories, mapped to MITRE ATT&CK v14 | For blue teams, SOC analysts and purple team exercises
Wazuh SIEM SOC Analyst Training Manual WITH THINGS A NEWBIE MUST KNOW BEFORE USING THE WAZUH.
Hands-on SOC case study covering malware alert triage, malware behavior analysis, incident response execution, IOC creation, and security control improvement using MITRE ATT&CK.
This portfolio focuses on my abilities how to deal with Tryhackme challenges / labs, which contain a full bunch of important programs and frameworks used in real life scenarios.
Automated Python script that parses Linux auth logs to detect SSH brute force attacks and generate incident reports
Global Enterprise Threat Intelligence & Incident Response Platform. Autonomous AI Security Analyst, Zero-Key VirusTotal/Shodan/AbuseIPDB Engines, SIEM Log Triage, Interactive Analyst Shell, EDR Telemetry & MITRE ATT&CK Visual Heatmaps.
Hey 👋, This Lab was made by Riad Moudjahed, a friendly malware analysis lab. "README" contains everything you need.
Hi, I'm Munnaza 👋
A hands-on SOC/XDR laboratory built using Wazuh, Ubuntu, Windows, and Sysmon. The project covers Wazuh SIEM deployment, Windows agent enrollment, Windows Event Log monitoring, Sysmon integration, Security Configuration Assessment (SCA), endpoint monitoring, detection engineering, threat hunting, and incident response. Future phases include vuln
Automated job search engine for remote, entry-level roles in cybersecurity, IT support, SOC analysis, and data labeling, scrapes 10+ job boards, filters by seniority and location eligibility, scores listings, and generates AI-tailored resumes via a local dashboard
Credentialed Nessus vulnerability assessment on a Windows 11 VM, with evidence screenshots, severity analysis, Graylog dashboard visualization, and a remediation plan. Demonstrates the full vulnerability management lifecycle from discovery to prioritization.
A comprehensive technical audit and penetration testing lab focused on SSH exploitation, MITRE ATT&CK mapping, and Linux forensic log analysis.
Performed Tier 1 SOC incident triage in Splunk Enterprise by analyzing Windows Security Event Logs and applying the Who, What, When, Where, and How methodology to investigate and assess security events.
Python tool that parses firewall logs and auto-detects port scans, brute-force attempts, and anomalous IPs — with charts and an HTML report generated automatically.
Python-based automated incident response framework ( Phishing analysis, Threat intel enrichment, IR playbooks, Vulnerability reporting, and NIST CSF compliance tracking.)
DexSentinel is a high-performance, real-time threat intelligence aggregator designed to provide global visibility into attack surface pressure. It correlates live telemetry with public OSINT feeds to offer a unified dashboard for security researchers and SOC analysts.
To associate your repository with the socanalyst topic, visit your repo's landing page and select "manage topics."