josue6368/portfolio

GitHub: josue6368/portfolio

一个涵盖 SIEM、威胁狩猎、漏洞管理、渗透测试等多个方向的网络安全实操项目作品集仓库。

Stars: 0 | Forks: 0

image
欢迎来到我的网络安全作品集。本仓库展示了涵盖检测工程、SIEM 分析、威胁狩猎、网络安全监控、漏洞管理、Web 应用安全、网络钓鱼模拟和密码安全的实操项目。 每个项目都包含了详细记录的工作流程、截图、发现结果以及分析过程,并使用了 Splunk、Zeek、Sysmon、Wireshark、Wazuh 和 Kali Linux 等行业安全工具,以展示在进攻性安全、防御性操作和安全监控方面的实践技能。 ## 项目
Detection Engineering Sigma Wazuh Lab

Detection Engineering: Sigma + Wazuh Lab

Developed and tested detection logic using Sigma rules and Wazuh to identify suspicious activity, validate alerts, and map detections to real-world security use cases.

Nessus Vulnerability Management Lab

Nessus Vulnerability Management Lab

Performed vulnerability scanning with Nessus, analyzed findings, prioritized risk, and documented remediation recommendations using a vulnerability management workflow.

Wazuh SIEM Home Lab

Wazuh SIEM Home Lab: Mini SOC Environment

Built a Wazuh-based mini SOC environment using Ubuntu, Windows, and Kali Linux to collect endpoint logs, analyze alerts, and map activity to MITRE ATT&CK techniques.

OWASP Juice Shop Web App Pentest

OWASP Juice Shop Web App Pentest

Conducted a web application penetration test against OWASP Juice Shop to identify common vulnerabilities, document exploitation steps, and provide security recommendations.

GoPhish Phishing Simulation Lab

GoPhish Phishing Simulation Lab

Built a phishing simulation lab using GoPhish to create campaigns, track user interaction, analyze results, and document security awareness training outcomes.

Password Cracking Policy Analysis Lab

Password Cracking & Policy Analysis Lab

Used password auditing techniques to evaluate password strength, analyze weak password patterns, and connect cracking results to stronger password policy recommendations.

Active Directory Attack and Defense Lab

Active Directory Attack & Defense Lab

Created an Active Directory lab focused on enterprise attack paths, Windows security monitoring, credential-based attacks, and defensive detection strategies.

Malware Traffic Analysis Lab

Malware Traffic Analysis Lab

Analyzed suspicious network traffic using Wireshark and PCAP files to identify indicators of compromise, malicious communication patterns, and infected host behavior.

Sysmon Splunk Threat Hunting Lab

Sysmon + Splunk Threat Hunting Lab

Configured Sysmon and Splunk Enterprise to collect Windows telemetry, investigate suspicious activity, and build practical threat-hunting searches.

Zeek Splunk Network Threat Hunting Lab

Zeek + Splunk Network Threat Hunting Lab

Built a Zeek + Splunk threat hunting lab to analyze malicious network traffic and investigate suspicious DNS, HTTP, and external IP activity.

Windows Privilege Escalation Lab

Windows Privilege Escalation & Detection Lab

Performed Windows privilege escalation analysis using PowerUp, validated vulnerable service configurations, and investigated activity through Sysmon and Splunk telemetry.

Coming Soon

More Projects Coming Soon

Additional cybersecurity labs will be added as they are completed, documented, and published.

## 展示技能 * 检测工程 * SIEM 部署与告警分析 * Sigma 规则创建与验证 * 使用 Splunk 进行威胁狩猎 * 使用 Sysmon 进行端点遥测分析 * 使用 Zeek 进行网络遥测分析 * 使用 Wireshark 进行网络流量分析 * 漏洞扫描与修复规划 * Web 应用渗透测试 * 网络钓鱼模拟与安全意识培训 * 密码审计与策略分析 * Windows 事件日志监控 * DNS 与 HTTP 流量分析 * Active Directory 安全概念 * MITRE ATT&CK 映射 * 事件响应文档记录 * 网络安全报告与作品集文档编写 ## 工具与技术

Wazuh Sigma Nessus Splunk Zeek Sysmon Wireshark GoPhish OWASP Kali Linux Windows Ubuntu VMware

标签:DAST, GPT, 安全运营, 恶意软件分析, 扫描框架, 漏洞管理, 网络安全实验