beathunterzero/beathunterzero

GitHub: beathunterzero/beathunterzero

面向威胁狩猎、检测工程与云事件响应的网络安全知识库及实验环境,提供从方法论到实操的完整参考。

Stars: 1 | Forks: 0

# 关于我: 专注于 Cyber Threat Hunting、Detection Engineering、DFIR 和 Cloud Incident Response 的网络安全专家。
我搭建安全实验室,记录调查工作流程,开发检测逻辑,并创建基于 Python 的安全工具以支持实战威胁分析。
我的工作遵循基于 MITRE ATT&CK、Cyber Kill Chain 和假设驱动狩猎的结构化方法论:了解对手行为,通过遥测数据对其进行验证,记录证据,并将其转化为可操作的检测规则。 ## 🌐 社交网络: [![Instagram](https://img.shields.io/badge/-Instagram-000?&logo=Instagram)](https://www.instagram.com/beathunterzero/) [![LinkedIn](https://img.shields.io/badge/-LinkedIn-000?&logo=LinkedIn)](https://www.linkedin.com/in/rhodyn-ildefonso-4ba73b1b8/) ## 🧰 技术栈与工具
🎯 Threat Hunting 与 Detection Engineering
![Threat Hunting](https://img.shields.io/badge/-Threat%20Hunting-000) ![Detection Engineering](https://img.shields.io/badge/-Detection%20Engineering-000) ![Hypothesis Driven Hunting](https://img.shields.io/badge/-Hypothesis--Driven%20Hunting-000) ![MITRE ATT&CK](https://img.shields.io/badge/-MITRE%20ATT%26CK-000) ![Cyber Kill Chain](https://img.shields.io/badge/-Cyber%20Kill%20Chain-000) ![Atomic Red Team](https://img.shields.io/badge/-Atomic%20Red%20Team-000) ![Sysmon](https://img.shields.io/badge/-Sysmon-000?&logo=microsoft)
🧪 DFIR 与 Incident Response
![DFIR](https://img.shields.io/badge/-DFIR-000) ![Incident Response](https://img.shields.io/badge/-Incident%20Response-000) ![NIST 800-61](https://img.shields.io/badge/-NIST%20800--61-000) ![Velociraptor](https://img.shields.io/badge/-Velociraptor-000) ![Volatility 3](https://img.shields.io/badge/-Volatility%203-000) ![Autopsy](https://img.shields.io/badge/-Autopsy-000) ![ProcDump](https://img.shields.io/badge/-ProcDump-000?&logo=microsoft) ![PagerDuty](https://img.shields.io/badge/-PagerDuty-000?&logo=pagerduty)
📊 SIEM、日志记录与检测平台
![Microsoft Sentinel](https://img.shields.io/badge/-Microsoft%20Sentinel-000?&logo=microsoftazure) ![KQL](https://img.shields.io/badge/-KQL-000?&logo=microsoftazure) ![Elastic Security](https://img.shields.io/badge/-Elastic%20Security-000?&logo=elastic) ![Elasticsearch](https://img.shields.io/badge/-Elasticsearch-000?&logo=elasticsearch) ![Kibana](https://img.shields.io/badge/-Kibana-000?&logo=kibana) ![Filebeat](https://img.shields.io/badge/-Filebeat-000?&logo=elastic) ![SOF-ELK](https://img.shields.io/badge/-SOF--ELK-000?&logo=elastic) ![Zeek](https://img.shields.io/badge/-Zeek-000) ![Wireshark](https://img.shields.io/badge/-Wireshark-000?&logo=wireshark)
☁️ 云安全
![AWS](https://img.shields.io/badge/-AWS-000?&logo=amazonwebservices) ![AWS GuardDuty](https://img.shields.io/badge/-AWS%20GuardDuty-000?&logo=amazonaws) ![AWS CloudTrail](https://img.shields.io/badge/-AWS%20CloudTrail-000?&logo=amazonaws) ![AWS WAF](https://img.shields.io/badge/-AWS%20WAF-000?&logo=amazonaws) ![VPC Flow Logs](https://img.shields.io/badge/-VPC%20Flow%20Logs-000?&logo=amazonaws) ![Azure](https://img.shields.io/badge/-Azure-000?&logo=microsoftazure) ![Microsoft Defender](https://img.shields.io/badge/-Microsoft%20Defender-000?&logo=microsoft) ![Defender for Cloud](https://img.shields.io/badge/-Defender%20for%20Cloud-000?&logo=microsoftazure) ![Oracle Cloud](https://img.shields.io/badge/-Oracle%20Cloud-000?&logo=oracle) ![Check Point CloudGuard](https://img.shields.io/badge/-Check%20Point%20CloudGuard-000)
🕵️ OSINT 与 Threat Intelligence
![OSINT](https://img.shields.io/badge/-OSINT-000) ![Threat Intelligence](https://img.shields.io/badge/-Threat%20Intelligence-000) ![VirusTotal](https://img.shields.io/badge/-VirusTotal-000?&logo=virustotal) ![AbuseIPDB](https://img.shields.io/badge/-AbuseIPDB-000) ![Shodan](https://img.shields.io/badge/-Shodan-000) ![Censys](https://img.shields.io/badge/-Censys-000) ![IBM X-Force](https://img.shields.io/badge/-IBM%20X--Force-000?&logo=ibm)
⚔️ 进攻性安全与验证
![Ethical Hacking](https://img.shields.io/badge/-Ethical%20Hacking-000) ![OWASP Top 10](https://img.shields.io/badge/-OWASP%20Top%2010-000?&logo=owasp) ![Burp Suite](https://img.shields.io/badge/-Burp%20Suite-000?&logo=burpsuite) ![OWASP ZAP](https://img.shields.io/badge/-OWASP%20ZAP-000?&logo=owasp) ![Nessus](https://img.shields.io/badge/-Nessus-000)
🛠️ 自动化与脚本
![Python](https://img.shields.io/badge/-Python-000?&logo=python) ![Bash](https://img.shields.io/badge/-Bash-000?&logo=gnubash) ![PowerShell](https://img.shields.io/badge/-PowerShell-000?&logo=powershell)
🧱 基础设施与实验室
![Docker](https://img.shields.io/badge/-Docker-000?&logo=docker) ![Docker Compose](https://img.shields.io/badge/-Docker%20Compose-000?&logo=docker) ![WSL2](https://img.shields.io/badge/-WSL2-000?&logo=linux) ![VMware](https://img.shields.io/badge/-VMware-000?&logo=vmware) ![Linux](https://img.shields.io/badge/-Linux-000?&logo=linux) ![Ubuntu](https://img.shields.io/badge/-Ubuntu-000?&logo=ubuntu) ![Debian](https://img.shields.io/badge/-Debian-000?&logo=debian) ![Fedora](https://img.shields.io/badge/-Fedora-000?&logo=fedora)
📚 框架与安全模型
![NIST CSF](https://img.shields.io/badge/-NIST%20CSF-000) ![NIST 800-61](https://img.shields.io/badge/-NIST%20800--61-000) ![ISO 27001](https://img.shields.io/badge/-ISO%2027001-000) ![Zero Trust](https://img.shields.io/badge/-Zero%20Trust-000) ![Defense in Depth](https://img.shields.io/badge/-Defense%20in%20Depth-000) ![MITRE ATT&CK](https://img.shields.io/badge/-MITRE%20ATT%26CK-000) ![Cyber Kill Chain](https://img.shields.io/badge/-Cyber%20Kill%20Chain-000)
## 🧪 精选项目 # 📊 GitHub 统计: ![](https://github-vercel-deployment-seven.vercel.app/api?username=beathunterzero&show_icons=true&theme=tokyonight&rank_icon=github&include_all_commits=true&count_private=true)
![](https://streak-stats.demolab.com/?user=beathunterzero&theme=tokyonight&hide_border=false)
标签:AI合规, Atomic Red Team, Cloudflare, MITRE ATT&CK, NIST 800-61, Python安全工具, Sysmon, Velociraptor, Volatility 3, 云应急响应, 假设驱动狩猎, 可操作检测, 威胁分析, 安全分析师, 安全实验室, 安全工具开发, 对手行为分析, 应用安全, 数字取证与应急响应, 数据泄露检测, 检测逻辑, 用户态调试, 管理员页面发现, 网络安全, 网络杀伤链, 自动化侦查工具, 请求拦截, 调查工作流, 越狱测试, 逆向工具, 遥测数据, 隐私保护