Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
SOC-Analyst-Portfolio — A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research. | Kitploit
Ferramentas/GitHubGitHub/0x0allenace/soc-analyst-portfolio
Malware AnalysisDigital ForensicsThreat IntelligenceMachine LearningLearning & EducationIncident ResponseCurated ResourcesEmail SecurityAnomaly Detection

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Log Analysis
Labs & Practice
GitHub0x0allenace/soc-analyst-portfolio

SOC-Analyst-Portfolio

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research.

Ver Repositório
217há 29 diasAinda não revisado
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Allen Ace Banner


🛡️ Allen Ace

SOC Analyst | Threat Hunter | Detection Engineer

Detect • Investigate • Respond • Defend

Welcome

This portfolio documents my hands-on cybersecurity journey through practical investigations, enterprise lab environments, detection engineering, digital forensics, malware analysis, threat hunting, and security analytics.

Each project demonstrates investigative methodology, security tooling, evidence correlation, detection development, and defensive thinking expected within a modern Security Operations Center (SOC).

Splunk Elastic Python Windows

MITRE ATT&CK Threat Hunting DFIR Digital Forensics Purple Team PowerShell

Table of Contents

  • About Me
  • Portfolio Highlights
  • Current Focus
  • Featured Projects
  • Technical Skills
  • Security Investigations
  • Malware Analysis
  • Email Security
  • Security Engineering
  • Security Tool Development
  • Detection Engineering
  • Certifications
  • Community
  • Cybersecurity Journey
  • Technical Articles
  • Video Walkthroughs
  • Portfolio Statistics
  • Contact

About Me

SOC Analyst with hands-on experience in Threat Hunting, Digital Forensics & Incident Response (DFIR), Detection Engineering, Malware Analysis, Security Analytics, and Python-based security tooling.

My work focuses on evidence-driven investigations, enterprise-style security monitoring, endpoint analysis, network analysis, malware investigations, memory forensics, and detection development aligned with the MITRE ATT&CK framework.

Portfolio Highlights

  • 10+ Enterprise-style Security Investigations
  • Purple Team Attack Simulation & Defensive Investigation
  • Static & Dynamic Malware Analysis
  • Memory Forensics with Volatility 3 & MemProcFS
  • Digital Forensics & Incident Response (DFIR)
  • Threat Hunting with Splunk & Elastic
  • Detection Engineering & SIEM Correlation
  • Network Traffic & PCAP Analysis
  • Security Analytics & Machine Learning
  • Python Security Automation
  • Technical Writing & Community Education

Current Focus

  • Detection Engineering
  • Threat Hunting
  • Purple Team Operations
  • Malware Analysis
  • Digital Forensics & Incident Response
  • Memory Forensics
  • Python Security Automation

Featured Projects

ProjectFocus AreaRepository
Purple Team Simulation 01Attack Simulation / Detection EngineeringView
Memory Forensics InvestigationMemory Forensics / DFIRView
Threat Hunting – ReconnaissanceSplunk Threat HuntingView
Enterprise DFIR LabIncident ResponseView
Velociraptor Forensic TriageEndpoint ForensicsView
Suspicious Email Attachment AnalysisEmail SecurityView
Static Malware AnalysisMalware AnalysisView
Windows Malware Behavioral AnalysisDynamic Malware AnalysisView
Behavioral Anomaly DetectionMachine LearningView
File Signature DetectorPython Security ToolView

🔗 Connect

  • 🔗 LinkedIn
  • 💻 GitHub

Technical Skills

DomainTechnologies
SIEMSplunk, Elastic Security
Threat HuntingSPL, EQL, KQL/Search-based Investigation, MITRE ATT&CK
Detection EngineeringSigma, SPL, EQL, Behavioral Detection, Sequence Detection
DFIRVelociraptor, KAPE, Autopsy, FTK Imager
Memory ForensicsVolatility 3, MemProcFS
Malware AnalysisPEStudio, Detect It Easy, FLOSS, Procmon, Process Explorer
Network AnalysisWireshark, PCAP Analysis, TCP/IP
Endpoint SecuritySysmon, Windows Event Logs, Elastic Defend
Purple TeamAttack Simulation, Defensive Validation, Detection Validation
ProgrammingPython, PowerShell
InfrastructureActive Directory, pfSense, Windows
Evidence AnalysisIOC Extraction, Timeline Reconstruction, Process Analysis

Security Investigations

Enterprise-style investigations demonstrating incident response, threat hunting, digital forensics, memory analysis, malware analysis, network forensics, and detection engineering.

Purple Team Simulation

Controlled adversary simulation followed by Blue Team detection, investigation, network forensics, and detection engineering.

Objective

Conduct a controlled PowerShell-based attack simulation within an isolated laboratory environment and evaluate whether endpoint and network telemetry could be used to detect, investigate, reconstruct, and respond to the attack.

Technologies

  • Elastic Security
  • Splunk
  • Sysmon
  • Wireshark
  • PowerShell
  • Kali Purple
  • Netcat
  • Python HTTP Server

Investigation Focus

  • PowerShell execution analysis
  • Windows process-tree reconstruction
  • Suspicious network activity
  • Reverse-shell detection
  • Network packet analysis
  • SIEM investigation
  • IOC identification
  • Timeline reconstruction
  • Detection engineering
  • Cross-tool evidence correlation

MITRE ATT&CK Mapping

TechniqueATT&CK ID
PowerShellT1059.001
Command and Scripting InterpreterT1059
Ingress Tool TransferT1105
System Owner/User DiscoveryT1033
System Information DiscoveryT1082
System Network Configuration DiscoveryT1016
Network Service ScanningT1046

Key Findings

Baixar ferramenta