Skip to content
View Hildevert's full-sized avatar
  • Joined Sep 7, 2026

Block or report Hildevert

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Hildevert/README.md

Hi there, I'm a Cybersecurity & SOC Analyst 🛡️

Analytical and hands-on Junior SOC Analyst / Blue Team Specialist focused on SIEM deployment, threat hunting, endpoint telemetry, network forensics, and security automation (SOAR).

Below is my operational hands-on cybersecurity portfolio built in a dedicated lab environment.


🛠️ Hands-On SOC & Threat Detection Portfolio

Project Core Stack Description & Key Skills
P1: Wazuh SIEM Deployment Wazuh, Linux, Syslog Deployed and configured a central SIEM manager to monitor endpoints, analyze security logs, and trigger rule alerts.
P2: Windows Security Hardening PowerShell, CIS Benchmarks Automated system hardening scripts aligning Windows 11 configurations with CIS security baselines.
P3: Network Forensics & PCAP Analysis Wireshark, TShark Analyzed network traffic captures to detect DNS tunneling, unencrypted credentials, and suspicious C2 communications.
P4: Phishing Triage & IoC Extraction CyberChef, MXToolbox Conducted email header analysis, evaluated SPF/DKIM/DMARC spoofing, and extracted obfuscated IoC payloads.
P5: Endpoint Telemetry & Sysmon Sysmon, Windows Events Configured Sysmon (SwiftOnSecurity baseline) to track process creation (Event ID 1) and flag obfuscated PowerShell execution.
P6: Automated Threat Intel (SOAR) VirusTotal API, PowerShell Scripted automated REST API queries to enrich suspicious IoCs, reducing MTTD and automating Level 1 triage workflows.

💻 Technical Skill Set

  • SIEM & Monitoring: Wazuh, Elastic Stack (ELK), Windows Event Viewer, Sysmon.
  • Network & Email Forensics: Wireshark, TShark, CyberChef, MXToolbox, SPF/DKIM/DMARC analysis.
  • Threat Intel & Automation: VirusTotal API v3, PowerShell Scripting, REST APIs, JSON parsing.
  • Frameworks & Standards: MITRE ATT&CK, CIS Benchmarks, NIST Incident Response Framework.

📬 Connect with me to discuss Blue Team operations, threat hunting, and SOC workflows!

Popular repositories Loading

  1. wazuh-siem-home-lab wazuh-siem-home-lab Public

    Enterprise-grade open-source SIEM lab deployed with Wazuh and VirtualBox to detect authentication anomalies and log telemetry in real time.

    1

  2. windows-cis-hardening-audit windows-cis-hardening-audit Public

    Automated Windows 11 security audit and CIS Benchmark hardening using PowerShell to mitigate brute-force and credential abuse.

    PowerShell 1

  3. network-traffic-analysis-wireshark network-traffic-analysis-wireshark Public

    Network traffic analysis and packet inspection using Wireshark to investigate DNS queries and network protocol behavior.

    1

  4. phishing-incident-response-triage phishing-incident-response-triage Public

    Phishing email analysis, header forensics, and IoC extraction for SOC Incident Response workflows.

    1

  5. sysmon-powershell-detection-lab sysmon-powershell-detection-lab Public

    Windows endpoint telemetry and threat detection lab using Sysmon to identify obfuscated PowerShell commands.

    1

  6. soar-automated-threat-intelligence soar-automated-threat-intelligence Public

    Automated threat intelligence ingestion and incident response playbook using VirusTotal API v3 for SOC workflows.

    1