███████╗██╗ ██╗██████╗ ██╗ ██╗ ██╗███████╗███████╗ ██╔════╝██║ ██║██╔══██╗██║ ██║ ██║██╔════╝██╔════╝ █████╗ ██║ ██║██████╔╝██║ ██║ ██║█████╗ ███████╗ ██╔══╝ ██║ ██║██╔═══╝ ██║ ██║ ██║██╔══╝ ╚════██║ ██║ ╚██████╔╝██║ ███████╗███████╗██║███████╗███████║ ╚═╝ ╚═════╝ ╚═╝ ╚══════╝╚══════╝╚═╝╚══════╝╚══════╝
Name: Jose
Classification: Security Operations Analyst (Aspiring Purple Team Engineer)
Primary Domain: Detection Engineering • Threat Hunting • DFIR
Secondary Domain: ⚔️Adversary Emulation • Red Teaming • Cloud Security • Identity Security
“Defenders don’t win by reacting faster — they win by understanding deeper.”
[✔] Detection Engineering → ACTIVE DEVELOPMENT [✔] Threat Hunting → ACTIVE OPERATIONS [✔] DFIR → ACTIVE INVESTIGATIONS [✔] SIEM Engineering → ACTIVE ANALYSIS [✔] Adversary Emulation → SIMULATION PHASE [✔] Cloud Security → EXPANDING COVERAGE [✔] Identity Security (AD) → CORE FOCUS
┌─────────────────────────────────────────────────────────────┐ │ SOC SIMULATION LAB → Detection Engineering + SIEM │ │ THREAT HUNTING LAB → Behavioral Analysis + Hypothesis │ │ DFIR LAB → Memory + Disk Forensics │ │ ACTIVE DIRECTORY LAB → Identity Attack & Defense │ │ CLOUD SECURITY LAB → Azure / AWS Telemetry Analysis │ │ PURPLE TEAM LAB → MITRE ATT&CK Adversary Simulation │ └─────────────────────────────────────────────────────────────┘
Reconnaissance ██████████░░░░░░░░░ 55% Initial Access ███████████░░░░░░░░ 60% Execution ████████████░░░░░░░ 65% Persistence ███████████░░░░░░░░ 60% Privilege Escalation ██████████░░░░░░░░░ 55% Lateral Movement ██████████░░░░░░░░░ 55% Exfiltration █████████░░░░░░░░░░ 50% Detection Coverage ████████████░░░░░░░ 70%
- Design and deploy detection logic for real-world threats
- Hunt adversaries using behavioral intelligence
- Investigate security incidents end-to-end (DFIR)
- Simulate attacker tradecraft using MITRE ATT&CK
- Strengthen enterprise detection and response capabilities
Here are the repositories where I showcase my work:
- 🔐 Windows Attack Telemetry Research Lab : Built a controlled Windows environment for generating, capturing, and analyzing attack telemetry. Focused on mapping attacker behavior to logs, improving detection engineering skills, and developing threat hunting hypotheses using real system activity. (This Project is still underdevelopment and will be provided soon!)
“You don’t stop attacks by reacting to them.
You stop them by understanding them before they happen.”