Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
-
Updated
Apr 13, 2026
Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your attack surface over time, and gate your CI/CD — all free.
ShadowWall AI is a cutting-edge, enterprise-grade cybersecurity platform that employs artificial intelligence, machine learning, and advanced deception techniques to provide comprehensive protection against sophisticated cyber threats. Designed for security professionals, SOC teams, and organizations requiring proactive threat defense.
A lightweight SOC-focused threat intelligence platform built with Python & Flask. Manage, search, and export IOCs (IPs, domains, file hashes) with live AbuseIPDB enrichment and an interactive dashboard.
Sigma-format SAST detection rules for Active Directory attack techniques — CLAUDE 94 rules across 14 categories, mapped to MITRE ATT&CK v14 | For blue teams, SOC analysts and purple team exercises
Wazuh SIEM SOC Analyst Training Manual WITH THINGS A NEWBIE MUST KNOW BEFORE USING THE WAZUH.
Automated Python script that parses Linux auth logs to detect SSH brute force attacks and generate incident reports
This portfolio focuses on my abilities how to deal with Tryhackme challenges / labs, which contain a full bunch of important programs and frameworks used in real life scenarios.
Hey 👋, This Lab was made by Riad Moudjahed, a friendly malware analysis lab. "README" contains everything you need.
Global Enterprise Threat Intelligence & Incident Response Platform. Autonomous AI Security Analyst, Zero-Key VirusTotal/Shodan/AbuseIPDB Engines, SIEM Log Triage, Interactive Analyst Shell, EDR Telemetry & MITRE ATT&CK Visual Heatmaps.
Python-based automated incident response framework ( Phishing analysis, Threat intel enrichment, IR playbooks, Vulnerability reporting, and NIST CSF compliance tracking.)
Automated job search engine for remote, entry-level roles in cybersecurity, IT support, SOC analysis, and data labeling, scrapes 10+ job boards, filters by seniority and location eligibility, scores listings, and generates AI-tailored resumes via a local dashboard
A comprehensive technical audit and penetration testing lab focused on SSH exploitation, MITRE ATT&CK mapping, and Linux forensic log analysis.
Documentation of my 3-month Cyberster Blue Team internship — covering SOC operations, SIEM lab setup (VirtualBox, Wazuh), network traffic analysis, detection rules, and incident response, building toward a Blue Team / SOC Analyst role."
Credentialed Nessus vulnerability assessment on a Windows 11 VM, with evidence screenshots, severity analysis, Graylog dashboard visualization, and a remediation plan. Demonstrates the full vulnerability management lifecycle from discovery to prioritization.
Python tool that parses firewall logs and auto-detects port scans, brute-force attempts, and anomalous IPs — with charts and an HTML report generated automatically.
Performed Tier 1 SOC incident triage in Splunk Enterprise by analyzing Windows Security Event Logs and applying the Who, What, When, Where, and How methodology to investigate and assess security events.
SOC Analyst IR Playbooks: Ransomware, Phishing, Brute Force, Malware, Data Exfiltration
Hands-on network traffic analysis lab using Wireshark and Kali Linux to capture, filter, and analyze ICMP and DNS traffic.
Add a description, image, and links to the socanalyst topic page so that developers can more easily learn about it.
To associate your repository with the socanalyst topic, visit your repo's landing page and select "manage topics."