This repository contains my hands-on work related to Security Operations Centers (SOC), focusing on SIEM tools, detection engineering, monitoring, and security automation.
- SIEM Dashboards (Splunk, ELK, Security Onion)
- Threat Detection (Sigma, Suricata, Zeek)
- Correlation Rules & Use Cases
- Automation Scripts (Python, Bash)
- Incident Response Templates
- Playbooks for Threat Response
- Threat Hunting Techniques
| Directory | Content |
|---|---|
| Splunk/ | Custom dashboards, correlation searches, saved queries |
| ELK-Stack/ | Kibana dashboards, Elasticsearch queries, detections |
| SecurityOnion/ | Suricata rules, Zeek scripts |
| Sigma-Rules/ | Cross-platform detection rules |
| Scripts/ | Automation for detection/response |
| Reports/ | Templates, playbooks, and IR documentation |
To demonstrate practical SOC capabilities through documented projects, detections, and automation relevant to modern enterprise environments.
- Splunk
- ELK Stack (Elasticsearch, Logstash, Kibana)
- Security Onion
- Suricata, Zeek
- Sigma Rules
- Python, Bash
This repository will grow as I expand my knowledge through practical labs, real-world scenarios, and continuous professional development.