Skip to content
View 4rthur-Root's full-sized avatar
😀
😀

Block or report 4rthur-Root

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
4rthur-Root/README.md

🇫🇷 Lire la version française

Hey, I'm Adrien 👋

SOC Analyst in Training • Detection Engineer • Blue Team Operator

Profile views


🎯 Mission

Security Operations Center (SOC) operator with a passion for detection engineering, threat hunting, and incident response. I build practical security labs that replicate real-world attack chains and defensive workflows.


🧭 About Me

  • 🎓 Computer Engineering student at École Polytechnique de Lomé — specializing in cybersecurity
  • 🔴 Blue Team Focus: SOC operations, detection engineering, SIEM correlation, threat hunting, incident response
  • 🟢 Red Team Awareness: Understanding attacker tactics (MITRE ATT&CK) to build better defenses
  • 🧪 Active in CTF competitions and online SOC platforms — forensics, malware analysis, log analysis
  • 🛠️ Building Blue Team Fusion Lab: 3-VM environment with Wazuh, Suricata, and Active Directory (AD) for simulating realistic attack scenarios and detection workflows
  • 🌱 Learning philosophy: Ship real systems, automate labs, solve detection engineering problems—not just follow tutorials

🚀 SOC & Detection Engineering Focus

  • SIEM & Log Analysis: Wazuh correlation rules, Suricata IDS signatures, multi-source event enrichment
  • Detection Engineering: Writing YAML-based detection rules, alert tuning, false positive reduction
  • Threat Hunting: Proactive threat searches using log aggregation, behavioral analysis, TTPs
  • Incident Response: Alert triage, root cause analysis, containment workflows, forensic collection
  • Windows Security: Event log analysis, Active Directory monitoring, privilege escalation detection
  • Network Forensics: Packet analysis, anomaly detection, traffic profiling, protocol inspection
  • SOAR & Automation: Automated response playbooks, OSINT enrichment, alert orchestration

🎯 Career Goals

  • 6-12 months: Junior SOC Analyst role — managing alerts, investigating incidents, tuning detection rules
  • 12-24 months: Detection Engineer or SOC Senior Analyst — designing SIEM workflows, threat hunting campaigns, detection logic
  • 2+ years: Security Architect or Threat Intel Analyst — strategy, advanced threat hunting, MITRE ATT&CK framework expertise

🧰 SOC & Detection Tools

🛠️ Infrastructure & Automation

🔧 Core SOC Competencies

Domain Skills
Detection SIEM rule design, Suricata/Snort IDS tuning, YARA malware signatures, alert correlation
Investigation Log analysis, event timeline reconstruction, root cause analysis, forensic data collection
Response Incident classification, containment actions, remediation workflows, post-incident reporting
Threat Intel MITRE ATT&CK mapping, adversary behavior analysis, TTP correlation, IoC enrichment
Platform Skills Wazuh (agent deployment, rules, dashboards), Grafana (visualization), Splunk/ELK (querying)
Automation Detection rule scripting, playbook development, Terraform/Ansible lab orchestration

🔦 Featured Projects

🛰️ NYX - SIEM Correlation Engine + SOAR

Production-ready Python SIEM correlation engine with automated incident response. Multi-source log ingestion, YAML-defined detection rules, YARA malware scanning, and Grafana dashboard for real-time alert visibility and metrics.

Why it matters for SOC roles: Demonstrates detection engineering, SOAR automation, and hands-on SIEM architecture.

Python Detection Engineering SOAR YARA Grafana Log Correlation

🛡️ DevSecOps Web Lab - Attack Simulation + Blue Team Monitoring

Fully automated infrastructure-as-code lab deploying a hardened web stack (Nginx/ModSecurity WAF, OWASP Juice Shop, MySQL) with centralized SOC monitoring (Wazuh, Suricata, Grafana/Loki). Includes realistic kill chain attack simulation for testing detections.

Why it matters for SOC roles: Showcases ability to build reproducible lab environments, deploy detection tools, and simulate adversary attacks for validation.

Terraform Ansible Wazuh Suricata Grafana/Loki Kill Chain Simulation OWASP Top 10

🖥️ Online Labs - SOC & CTF Training Portfolio

Curated hands-on training across multiple SOC platforms (HackTheBox, TryHackMe, CyberDefenders) and forensic labs. Includes walkthroughs, detection techniques, and investigation methodologies.

Why it matters for SOC roles: Demonstrates continuous learning in detection engineering, forensics, and incident investigation.

Forensic Analysis Threat Hunting Log Analysis Malware Investigation CyberDefenders

🖥️ Cyber Lab - VM Lab Orchestrator (team project)

Java desktop application for managing VirtualBox-based security labs. Provides VM grouping, timestamped analyst notes, and structured PDF reporting—designed for SOC training environments.

Java 17 SQLite VBoxManage Design Patterns


📚 Current Learning & Growth

  • Threat Hunting: Building queries for Wazuh/Splunk to hunt for lateral movement and persistence TTPs
  • Detection Rule Writing: Expanding YAML-based detection rules covering MITRE ATT&CK tactics
  • Windows Event Log Analysis: Deep dive into security event logs, Kerberos analysis, and AD attacks
  • Incident Response Playbooks: Documenting IR workflows for malware, data exfiltration, and ransomware
  • Advanced SIEM Features: ELK stack, Splunk SPL, detection testing frameworks

🎓 Certifications & Training Targets

  • 📅 Planned: Google Cloud Security (Coursera)
  • 📅 Planned: Splunk Fundamentals
  • 🎯 Goal: CompTIA Security+ or CEH (later)
  • 📍 Current: Active on CyberDefenders (forensics and SOC labs)

📊 GitHub Stats


📫 Connect With Me


🔍 Always analyzing. 🚨 Always ready. 📊 Always learning.

Pinned Loading

  1. NYX NYX Public

    Python-based SIEM correlation engine with automated SOAR response — stateful multi-source log analysis, YAML detection rules, and YARA integration and dashboard view with grafana

    Python 1

  2. Online-Labs Online-Labs Public

    A curated hub for all the labs I am doing online on leading plateforms like THM, HTB, BTLO, Let's defend and so on 💥. Also , it includes the journey to my certifications 🖺. Ulitmately , It does als…

    Shell

  3. DevSecOps-web-lab DevSecOps-web-lab Public

    Automated deployment of a secured web stack using Terraform (Docker provider) and Ansible. Features a WAF (Nginx + ModSecurity + OWASP CRS) in front of OWASP Juice Shop, with centralized log monito…

    Shell 2

  4. CyberLab CyberLab Public

    Desktop app to manage VirtualBox VM labs for security analysts - organize VMs by lab, control snapshots, keep timestamped analysis notes, and export PDF reports. Built with JavaFX + SQLite.

    Java 2