Skip to content

Latest commit

ย 

History

15 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 

Repository files navigation

Hi I'm Keshon! ๐Ÿ‘‹

Programmer | Cybersecurity Professional | SOC Analyst


image About Me

I'm a security-focused developer dedicated to automating the mundane and hunting the sophisticated. Currently spending my time building automated defense pipelines and exploring adversary emulation.

  • ๐Ÿ”ญ Iโ€™m currently working on Advanced SOC Playbooks
  • ๐ŸŒฑ Iโ€™m currently learning Cloud Security Architecture
  • ๐Ÿ’ฌ Ask me about Automation, SIEM, or Malware Analysis

๐Ÿ› ๏ธ Tech Stack

Python Bash Linux Wazuh Splunk Wireshark Metasploit Nmap


image Key Cybersecurity Projects

๐Ÿ›ก๏ธ Malware Triage Framework

Automates the analysis of malware samples for both Windows and Linux targets, providing rapid identification of families, binary characteristics, and potential C2 infrastructure without executing the malware.

  • Problem Solved: Reduces manual effort in malware triage, enabling faster and safer identification of threats across multiple platforms.

  • Key Features:

    • Automatic folder watcher for new samples
    • YARA-based family detection
    • PE and ELF parsing with architecture, entropy, and packing analysis
    • XOR-based Mirai C2 extraction with scoring
    • Generic fallback extractor for unknown malware
    • Professional JSON reports and clean terminal output
  • Tools & Tech: Python, YARA, pefile, watchdog, XOR decoding, JSON reporting

Bridge the gap between detection and response by routing Wazuh Manager alerts to mobile devices via the Telegram Bot API.

  • Problem Solved: Reduces the delay in seeing critical security events when away from the SIEM console.
  • Key Features: Customizable alert levels (e.g., only Level 7+), JSON parsing, and asynchronous message delivery.
  • Tools: Python, Wazuh Framework, Telegram API.

A hands-on laboratory environment for simulating and detecting Advanced Persistent Threat (APT) behaviors within a Windows Domain environment.

  • Goal: Identify blind spots in default Windows logging and implement advanced telemetry (Sysmon).
  • Techniques Simualted: Pass-the-Hash, SMB Relay, and RDP Hijacking.
  • Defensive Stack: Splunk, Windows Event Forwarding (WEF), and Snort.

๐Ÿคณ Connect with me

Keshon | LinkedIn

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors