Blue Team | Detection Engineering | Incident Response
Core stack:
I'm William, a detection engineer and SOC analyst (early-career) focused on defensive security, detection engineering, and incident response. This repository documents structured, hands-on work across the Blue Team skill stack: alert triage, log analysis, SIEM investigations, detection authoring, and threat hunting.
Every project here is built to mirror the workflows of a working SOC, not tutorial replays. These are lab environments, and where a project's scope is limited, its README says so. The goal is demonstrable competence: detections I've written, incidents I've walked through end-to-end, and tooling I can speak to in an interview.
Certifications: ISC2 Certified in Cybersecurity (CC) | CompTIA Security+ (in progress)
Two detection gaps reported to SigmaHQ, validated against real telemetry from my own lab.
| Issue | Technique | Finding |
|---|---|---|
| SigmaHQ #6056 | T1071.001 | False positive - Sysmon EID 3 firing on legitimate Azure traffic |
| SigmaHQ #6057 | T1136.001 | Coverage gap - ADSI/WinNT local user creation, Windows 4104 |
Both reported by me. The remediation PR was opened by a community contributor.
The detection, triage, and incident response work most representative of day-to-day SOC and detection engineering operations.
|
Host + network detection with custom Wazuh, Suricata & PowerShell rules
|
Cloud SIEM with KQL analytics rules & threat hunting
|
NHI abuse, prompt injection & MCP attack chain detection
|
|
Splunk SIEM detection & log analysis for credential attacks
|
Detection-as-code & portable Sigma rule authoring
|
Email triage & IOC extraction workflow
|
|
Splunk SIEM Alerts & Dashboard Alert engineering & real-time SOC dashboards
|
IR workflow & containment procedures
|
Packet inspection & C2 detection with Wireshark
|
|
End-to-end shift with campaign correlation
|
MITRE ATT&CK Detection Coverage Detection mapping & coverage gap analysis
|
|
Recon detection with Wireshark |
Endpoint log triage |
Linux Log Analysis & File Integrity Host integrity monitoring |
|
Identity attack detection |
Malware Analysis & Threat Hunting Threat hunting |
Vulnerability Scanning & Remediation Vuln management |
|
Network defense |
Automation & scripting |
Threat intel |
|
AWS Cloud Security Investigation Cloud detection with CloudTrail |
55 curated tools across 13 sections |
DFIR Bash modules |
|
Bash automation, Nmap detection & Python OSINT |
36 IOCs across 14 labs |
Log parsing & SPL |
|
EDR & endpoint detection |
Digital Forensics Investigation Digital forensics & incident response |
SOC reporting |
|
Advanced Splunk Intelligence Platform Advanced SIEM |
Build a real-world detection engineering and SOC portfolio through hands-on detection, investigation, and documentation, and land an entry-level Blue Team role.
Open to networking and collaboration in cybersecurity and Blue Team learning.
