
SOC-Analyst-Portfolio
A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

ThePhish: an automated phishing email analysis tool

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

just idea, no cp pls

MX Server misconfiguration

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…