Skip to content
View songagona2017-ops's full-sized avatar

Block or report songagona2017-ops

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
songagona2017-ops/README.md

Hi, I'm Nick Songa πŸ‘‹

Typing SVG

profile views

BTL1 Security+ Cert IV


πŸ›‘οΈ About me

  • πŸ” Cyber security analyst focused on defensive security β€” detection engineering, log analysis, triage, and incident response.
  • 🧰 Former IT Specialist and digital skills trainer β€” I bring real IT grounding and the ability to explain security to non-technical people.
  • 🎯 Currently seeking a junior SOC analyst / blue team role (Melbourne & remote).
  • πŸ“š Always building: I learn by turning concepts into working detections and tools, not just theory.

πŸŽ“ Certifications

  • βœ… Blue Team Level 1 (BTL1) β€” Security Blue Team
  • βœ… CompTIA Security+
  • βœ… Certificate IV in Cyber Security
  • βœ… CCNA β€” Cisco Certified Network Associate

🧠 Skills & Tools

My Skills

Security stack:

MITRE ATT&CK Splunk Sentinel Wazuh Sigma Python Linux Windows Wireshark

Domains: SIEM & log analysis Β· Detection engineering Β· Incident response Β· Threat intelligence Β· Windows/Linux security Β· Network fundamentals


πŸ—ΊοΈ Skills β†’ Projects

Skill Where I demonstrate it
Detection engineering (Sigma / SPL / KQL) Detection Engineering Lab
MITRE ATT&CK mapping & triage playbooks Detection Engineering Lab
Python security tooling SOC Analyst Toolkit
Log parsing & brute-force detection SOC Analyst Toolkit
SIEM deployment & attack simulation Home SOC Lab
Incident response, forensics & threat intel Blue Team Labs
Phishing triage & email authentication (SPF/DKIM/DMARC) Phishing Analyzer
AI / LLM security testing AI Security Scanner

πŸš€ Featured Projects

Project What it demonstrates
πŸ§ͺ Blue Team Labs 5 hands-on SOC labs β€” incident response & triage, phishing analysis, MISP threat intel, Splunk SIEM, digital forensics. The full detect β†’ investigate β†’ contain β†’ report workflow.
🎯 Detection Engineering Lab SIEM detection rules in Sigma β†’ Splunk SPL β†’ Sentinel KQL, mapped to MITRE ATT&CK, each with sample logs & analyst triage playbooks.
🎣 Phishing Analyzer Python CLI that parses email headers (SPF/DKIM/DMARC), extracts IOCs, and risk-scores a .eml β€” CRITICAL vs LOW verdicts, with sample emails & unit tests.
🐍 SOC Analyst Toolkit Python tool: parse auth logs, detect brute force, enrich IOCs, output triage reports. Dependency-free & tested.
🏠 Home SOC Lab Documented Wazuh SIEM lab β€” simulate attacks, detect with ATT&CK-mapped rules, respond.
πŸ€– AI Security Scanner LLM red-teaming tool β€” automated prompt-injection vulnerability detection.

πŸ“Š GitHub Stats

stats top langs

streak

trophies


🀝 Connect

LinkedIn GitHub

β€œDefenders think in graphs, attackers think in steps β€” I'm learning to do both.”

Popular repositories Loading

  1. ai-security-scanner ai-security-scanner Public

    LLM Red Teaming Tool β€” Automated prompt injection vulnerability detection for AI language models

    Python 1

  2. detection-engineering-lab detection-engineering-lab Public

    Detection rules (Sigma + Splunk SPL + Sentinel KQL) mapped to MITRE ATT&CK, with sample logs and triage playbooks.

  3. soc-toolkit soc-toolkit Public

    Python SOC toolkit: parse auth logs, detect SSH brute force, enrich IOCs, and output triage reports. Stdlib-only and tested.

    Python

  4. home-soc-lab home-soc-lab Public

    Documented home SOC lab (Wazuh + Windows + Kali): simulate attacks, detect with ATT&CK-mapped rules, and respond.

  5. songagona2017-ops songagona2017-ops Public

    ✨ Special profile repo β€” powers the landing page at github.com/songagona2017-ops

  6. blue-team-labs blue-team-labs Public

    Hands-on blue-team / SOC analyst labs: incident response, phishing analysis, MISP threat intel, Splunk SIEM, and digital forensics write-ups.