I’m currently working on Detection engineering & threat intelligence in a multi-tenant Elastic SIEM environment 👯 I’m looking to collaborate on Open-source SIEM detection rules, threat intel tooling, or security automation projects 🤝 I’m looking for help with Mid-level Cybersecurity Analyst / Security Engineer remote roles 🌱 I’m currently learning Threat hunting techniques, SOAR automation, and cloud security (Azure/GCP) 💬 Ask me about Elastic SIEM, detection engineering, KQL/SPL, threat intelligence (MISP, AbuseCH), or building security tools in Python/React ⚡ Fun fact I built an impossible travel detection system that flags geo-jump anomalies across global login events in real time
🎯
Focusing
Pinned Loading
-
elastic-detection-rules
elastic-detection-rules PublicProduction-tested Elastic Security detection rules (ES|QL/KQL) with MITRE ATT&CK mappings, tuning guidance, and triage playbooks
-
elastic-impossible-travel-detection
elastic-impossible-travel-detection PublicElastic SIEM detection rule to identify impossible travel login activity across Microsoft 365 and Azure AD, helping detect credential compromise through geo-velocity anomaly monitoring.
-
Malware-Behavior-Analysis-Capstone-Project
Malware-Behavior-Analysis-Capstone-Project PublicMalware Behavior Analysis Capstone Project
Python
-
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.