欢迎来到我的网络安全作品集。本仓库展示了涵盖检测工程、SIEM 分析、威胁狩猎、网络安全监控、漏洞管理、Web 应用安全、网络钓鱼模拟和密码安全的实操项目。
每个项目都包含了详细记录的工作流程、截图、发现结果以及分析过程,并使用了 Splunk、Zeek、Sysmon、Wireshark、Wazuh 和 Kali Linux 等行业安全工具,以展示在进攻性安全、防御性操作和安全监控方面的实践技能。
## 项目
Detection Engineering: Sigma + Wazuh Lab
Developed and tested detection logic using Sigma rules and Wazuh to identify suspicious activity, validate alerts, and map detections to real-world security use cases.
|
Nessus Vulnerability Management Lab
Performed vulnerability scanning with Nessus, analyzed findings, prioritized risk, and documented remediation recommendations using a vulnerability management workflow.
|
Wazuh SIEM Home Lab: Mini SOC Environment
Built a Wazuh-based mini SOC environment using Ubuntu, Windows, and Kali Linux to collect endpoint logs, analyze alerts, and map activity to MITRE ATT&CK techniques.
|
OWASP Juice Shop Web App Pentest
Conducted a web application penetration test against OWASP Juice Shop to identify common vulnerabilities, document exploitation steps, and provide security recommendations.
|
GoPhish Phishing Simulation Lab
Built a phishing simulation lab using GoPhish to create campaigns, track user interaction, analyze results, and document security awareness training outcomes.
|
Password Cracking & Policy Analysis Lab
Used password auditing techniques to evaluate password strength, analyze weak password patterns, and connect cracking results to stronger password policy recommendations.
|
Active Directory Attack & Defense Lab
Created an Active Directory lab focused on enterprise attack paths, Windows security monitoring, credential-based attacks, and defensive detection strategies.
|
Malware Traffic Analysis Lab
Analyzed suspicious network traffic using Wireshark and PCAP files to identify indicators of compromise, malicious communication patterns, and infected host behavior.
|
Sysmon + Splunk Threat Hunting Lab
Configured Sysmon and Splunk Enterprise to collect Windows telemetry, investigate suspicious activity, and build practical threat-hunting searches.
|
Zeek + Splunk Network Threat Hunting Lab
Built a Zeek + Splunk threat hunting lab to analyze malicious network traffic and investigate suspicious DNS, HTTP, and external IP activity.
|
Windows Privilege Escalation & Detection Lab
Performed Windows privilege escalation analysis using PowerUp, validated vulnerable service configurations, and investigated activity through Sysmon and Splunk telemetry.
|
More Projects Coming Soon
Additional cybersecurity labs will be added as they are completed, documented, and published.
|
## 展示技能
* 检测工程
* SIEM 部署与告警分析
* Sigma 规则创建与验证
* 使用 Splunk 进行威胁狩猎
* 使用 Sysmon 进行端点遥测分析
* 使用 Zeek 进行网络遥测分析
* 使用 Wireshark 进行网络流量分析
* 漏洞扫描与修复规划
* Web 应用渗透测试
* 网络钓鱼模拟与安全意识培训
* 密码审计与策略分析
* Windows 事件日志监控
* DNS 与 HTTP 流量分析
* Active Directory 安全概念
* MITRE ATT&CK 映射
* 事件响应文档记录
* 网络安全报告与作品集文档编写
## 工具与技术