Skip to content
View H3NRYBAIT's full-sized avatar

Block or report H3NRYBAIT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
H3NRYBAIT/README.md

Typing SVG


Medium LinkedIn GitHub Profile Views


analyst = {
    "alias"          : "H3NRY B41T",
    "role"           : ["CTI Analyst", "SOC Analyst", "OSINT Researcher"],
    "certifications" : ["CC — (ISC)2", "CNSP — Certified Network Security Practitioner"],
    "current"        : "30-Day Self-Study CTI Program — Live Threat Investigations",
    "method"         : "Passive OSINT only — no active exploitation",
    "open_to"        : ["CTI Internships", "SOC Roles", "Remote Opportunities"]
}

> SKILLS

SIEM & Detection

Wazuh Elasticsearch Kibana Logstash

Wazuh                  ████████████████████  100%
Elasticsearch/Kibana   ████████████████████  100%
ELK Stack              ██████████████████░░   90%
Custom Alert Rules     ████████████████████  100%
Event Correlation      ████████████████████  100%

Threat Intelligence & OSINT

VirusTotal Shodan Censys MITRE AlienVault

Infrastructure Pivoting   ████████████████████  100%
Passive DNS Analysis      ████████████████████  100%
Certificate Intelligence  ████████████████████  100%
MITRE ATT&CK Mapping      ████████████████████  100%
Imphash / Clustering      ████████████████░░░░   80%
IOC Documentation         ████████████████████  100%

Malware Analysis

MalwareBazaar AnyRun REMnux

Behavioral Analysis       ████████████████░░░░   80%
Sandbox Analysis          ████████████████░░░░   80%
C2 Infrastructure         ████████████████████  100%
REMnux / FLARE VM         ████████████░░░░░░░░   60%

Network Security & IR

Suricata Wireshark TheHive MISP

Suricata IDS/IPS          ████████████████████  100%
pfSense / Squid Proxy     ██████████████████░░   90%
Wireshark                 ████████████████░░░░   80%
TheHive / MISP / Cortex   ████████████████░░░░   80%

Automation & Tools

Python Docker n8n Linux

Python                    ████████████████░░░░   80%
n8n Automation            ████████████████░░░░   80%
Docker                    ████████████░░░░░░░░   60%
Linux CLI                 ████████████████████  100%

> PROJECTS

threatpivot Multi-source IOC enrichment and pivot tool for threat intelligence analysts. No Docker, no server — pip install and go.

Python Repo

SOC Automation — AI Threat Detection Wazuh + n8n + LLaMA 3 pipeline. Automated alert triage with live dashboard. Reduced alert noise and improved detection speed.

Wazuh n8n

Automated Threat Intelligence Workflow n8n pipeline with IP validation via AbuseIPDB and real-time Slack alerts for SOC triage automation.

n8n AbuseIPDB

Automated Malware Analysis Pipeline Docker + Wazuh + Cortex + MISP + Python. End-to-end SOC pipeline validated with simulated SSH brute-force.

Docker MISP


> CERTIFICATIONS

CC CNSP


> APPROACH

START    >>  Single IOC — URL, hash, domain, or IP
PIVOT    >>  Infrastructure fingerprinting
CLUSTER  >>  Passive DNS · certificate transparency · imphash
MAP      >>  Full operator infrastructure
DOCUMENT >>  IOCs · ATT&CK mapping · OPSEC failures
PUBLISH  >>  Medium write-up + GitHub IOC release

The attacker's biggest advantage is that defenders
look at indicators individually.

The analyst's biggest advantage is that attackers
reuse infrastructure.

Find the reuse. Pull the thread.

[ OPEN TO: CTI INTERNSHIPS · SOC ROLES · REMOTE OPPORTUNITIES ]
[ PASSIVE OSINT ONLY · NO UNAUTHORIZED ACCESS · FREE TOOLS ONLY ]

Popular repositories Loading

  1. threatpivot threatpivot Public

    Multi-source IOC enrichment and pivot tool for threat intelligence analysts — no Docker, no server, pip install and go

    Python 1

  2. 4-week-cti-learning-journey 4-week-cti-learning-journey Public

    A 30-day self-study Cyber Threat Intelligence program. Weekly case studies, IOCs, and investigations using free passive OSINT tools only.

    YARA

  3. H3NRYBAIT H3NRYBAIT Public