
Microsoft-Sentinel-SecOps
SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.

eBPF-based daemon to mitigate CVE-2026-31431 on systems where `algif_aead` is built into the kernel, without a reboot!

ML-driven threat detection and continuous monitoring platform built for federal zero trust architectures.

Tuning and refactoring Google Chronicle Curated Detections to eliminate alert fatigue and fix logic gaps/bugs.

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Open source solutions for SOC2, GDPR, and ISO27001

Summary of Cyber Security interview questions I have been through, hope this helps

Purple Team Exercise Framework

Automatically generated Sysmon parser for Azure Sentinel

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

Repository of attack and defensive information for Business Email Compromise investigations

Chronicle parser for CORELIGHT and related information.

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…