analyst = {
"alias" : "H3NRY B41T",
"role" : ["CTI Analyst", "SOC Analyst", "OSINT Researcher"],
"certifications" : ["CC — (ISC)2", "CNSP — Certified Network Security Practitioner"],
"current" : "30-Day Self-Study CTI Program — Live Threat Investigations",
"method" : "Passive OSINT only — no active exploitation",
"open_to" : ["CTI Internships", "SOC Roles", "Remote Opportunities"]
}Wazuh ████████████████████ 100%
Elasticsearch/Kibana ████████████████████ 100%
ELK Stack ██████████████████░░ 90%
Custom Alert Rules ████████████████████ 100%
Event Correlation ████████████████████ 100%
Infrastructure Pivoting ████████████████████ 100%
Passive DNS Analysis ████████████████████ 100%
Certificate Intelligence ████████████████████ 100%
MITRE ATT&CK Mapping ████████████████████ 100%
Imphash / Clustering ████████████████░░░░ 80%
IOC Documentation ████████████████████ 100%
Behavioral Analysis ████████████████░░░░ 80%
Sandbox Analysis ████████████████░░░░ 80%
C2 Infrastructure ████████████████████ 100%
REMnux / FLARE VM ████████████░░░░░░░░ 60%
Suricata IDS/IPS ████████████████████ 100%
pfSense / Squid Proxy ██████████████████░░ 90%
Wireshark ████████████████░░░░ 80%
TheHive / MISP / Cortex ████████████████░░░░ 80%
Python ████████████████░░░░ 80%
n8n Automation ████████████████░░░░ 80%
Docker ████████████░░░░░░░░ 60%
Linux CLI ████████████████████ 100%
|
threatpivot Multi-source IOC enrichment and pivot tool for threat intelligence analysts. No Docker, no server — pip install and go. |
SOC Automation — AI Threat Detection Wazuh + n8n + LLaMA 3 pipeline. Automated alert triage with live dashboard. Reduced alert noise and improved detection speed. |
|
Automated Threat Intelligence Workflow n8n pipeline with IP validation via AbuseIPDB and real-time Slack alerts for SOC triage automation. |
Automated Malware Analysis Pipeline Docker + Wazuh + Cortex + MISP + Python. End-to-end SOC pipeline validated with simulated SSH brute-force. |
START >> Single IOC — URL, hash, domain, or IP
PIVOT >> Infrastructure fingerprinting
CLUSTER >> Passive DNS · certificate transparency · imphash
MAP >> Full operator infrastructure
DOCUMENT >> IOCs · ATT&CK mapping · OPSEC failures
PUBLISH >> Medium write-up + GitHub IOC release
The attacker's biggest advantage is that defenders
look at indicators individually.
The analyst's biggest advantage is that attackers
reuse infrastructure.
Find the reuse. Pull the thread.
[ OPEN TO: CTI INTERNSHIPS · SOC ROLES · REMOTE OPPORTUNITIES ]
[ PASSIVE OSINT ONLY · NO UNAUTHORIZED ACCESS · FREE TOOLS ONLY ]
