Skip to content
View WiLL75G's full-sized avatar
🕵️
Blue Team | Detection Engineering | Incident Response
🕵️
Blue Team | Detection Engineering | Incident Response

Block or report WiLL75G

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
WiLL75G/README.md

Detection Engineering & SOC Portfolio

Blue Team | Detection Engineering | Incident Response

Core stack:

SIEM & Detection

Splunk SPL Microsoft Sentinel Microsoft Azure KQL Wazuh Suricata Sigma

Endpoint & Network

Sysmon Wireshark Nmap PowerShell Bash Python Linux

IR & Frameworks

ServiceNow MITRE ATT&CK


About Me

I'm William, a detection engineer and SOC analyst (early-career) focused on defensive security, detection engineering, and incident response. This repository documents structured, hands-on work across the Blue Team skill stack: alert triage, log analysis, SIEM investigations, detection authoring, and threat hunting.

Every project here is built to mirror the workflows of a working SOC, not tutorial replays. These are lab environments, and where a project's scope is limited, its README says so. The goal is demonstrable competence: detections I've written, incidents I've walked through end-to-end, and tooling I can speak to in an interview.

Certifications: ISC2 Certified in Cybersecurity (CC) | CompTIA Security+ (in progress)


Upstream Contributions

Two detection gaps reported to SigmaHQ, validated against real telemetry from my own lab.

Issue Technique Finding
SigmaHQ #6056 T1071.001 False positive - Sysmon EID 3 firing on legitimate Azure traffic
SigmaHQ #6057 T1136.001 Coverage gap - ADSI/WinNT local user creation, Windows 4104

Both reported by me. The remediation PR was opened by a community contributor.


Featured Projects

The detection, triage, and incident response work most representative of day-to-day SOC and detection engineering operations.

Detection Engineering Labs

Host + network detection with custom Wazuh, Suricata & PowerShell rules

T1110 T1046 T1059.001

Microsoft Sentinel SOC Lab

Cloud SIEM with KQL analytics rules & threat hunting

T1110 T1059.001

AI Era Detection Lab

NHI abuse, prompt injection & MCP attack chain detection

Multi-technique

SSH Brute Force Detection

Splunk SIEM detection & log analysis for credential attacks

T1110

Sigma Detection Lab

Detection-as-code & portable Sigma rule authoring

Multi-technique

Phishing Email Analysis

Email triage & IOC extraction workflow

T1566

Splunk SIEM Alerts & Dashboard

Alert engineering & real-time SOC dashboards

T1548.003 T1053.003

Incident Response Playbooks

IR workflow & containment procedures

T1110 T1566 T1204

Network Traffic Analysis

Packet inspection & C2 detection with Wireshark

T1219 T1071.001

SOC Shift Simulation Capstone

End-to-end shift with campaign correlation

Full chain

MITRE ATT&CK Detection Coverage

Detection mapping & coverage gap analysis

Coverage


Additional Projects

Network Port Scan Detection

Recon detection with Wireshark

Windows Event Log Analysis

Endpoint log triage

Linux Log Analysis & File Integrity

Host integrity monitoring

Password Spray Detection

Identity attack detection

Malware Analysis & Threat Hunting

Threat hunting

Vulnerability Scanning & Remediation

Vuln management

Firewall Hardening

Network defense

PowerShell SOC Toolkit

Automation & scripting

Threat Intelligence & OSINT

Threat intel

AWS Cloud Security Investigation

Cloud detection with CloudTrail

SOC Analyst Toolkit

55 curated tools across 13 sections

Linux Triage Toolkit

DFIR Bash modules

CorpOps Shell Suite

Bash automation, Nmap detection & Python OSINT

SOC IOC Tracker

36 IOCs across 14 labs

Regex Log Parsing Toolkit

Log parsing & SPL

Wazuh EDR Lab

EDR & endpoint detection

Digital Forensics Investigation

Digital forensics & incident response

SOC Metrics Dashboard

SOC reporting

Advanced Splunk Intelligence Platform

Advanced SIEM


Goal

Build a real-world detection engineering and SOC portfolio through hands-on detection, investigation, and documentation, and land an entry-level Blue Team role.


LinkedIn X Medium

Open to networking and collaboration in cybersecurity and Blue Team learning.

Pinned Loading

  1. WiLL75G WiLL75G Public

    SOC home lab: Splunk + Wazuh SIEM, Windows 11, Kali, Ubuntu Server. Detection engineering, threat hunting, and incident response mapped to MITRE ATT&CK with Sysmon and Sigma rules.

    6

  2. soc-day01-ssh-brute-force-detection soc-day01-ssh-brute-force-detection Public

    SSH brute force attack detection using log analysis and SOC investigation techniques.

    2

  3. soc-day09-incident-response-playbook soc-day09-incident-response-playbook Public

    Building a structured incident response playbook for SOC operations

    2

  4. soc-day10-mitre-attack-mapping soc-day10-mitre-attack-mapping Public

    Mapping security events to MITRE ATT&CK framework techniques

    2

  5. soc-day02-phishing-email-analysis soc-day02-phishing-email-analysis Public

    Analysis of suspicious emails to identify phishing indicators and malicious content

    2 1

  6. soc-day08-splunk-siem-alerts-dashboard soc-day08-splunk-siem-alerts-dashboard Public

    Creating SIEM alerts and dashboards using Splunk

    1