
Sentora
An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Reproducible SOC lab for CVE-2024-4577 detection and response

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs,…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A lightweight, real-time Security Information and Event Management (SIEM) dashboard built using Streamlit. It collects system logs, detects USB and…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Awesome list of keywords and artifacts for Threat Hunting sessions

A python package for use in generating fake data for SOC and security automation.

Useful resources for SOC Analyst and SOC Analyst candidates.

AI 驱动的 SOC 仿真平台

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…