A 30-day hands-on SOC Analyst project simulating real-world cyber attacks using ELK Stack, Mythic C2, osTicket & Elastic Defend. Covers threat detection, log analysis, incident response, and cloud-based SOC setup to bridge academic theory with practical cybersecurity skills.
☆45Jun 10, 2025Updated last year
Alternatives and similar repositories for 30-Day-SOC-Analyst-Challenge
Users that are interested in 30-Day-SOC-Analyst-Challenge are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- ☆62Jun 18, 2025Updated last year
- Comprehensive SOC Analyst notes covering incident response, threat hunting, SOC workflows, and cybersecurity concepts—perfect for exam pr…☆147Feb 26, 2026Updated 6 months ago
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated last month
- A specialized environment for crafting, validating, and testing LimaCharlie detection rules☆15Aug 21, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆99Jan 7, 2026Updated 8 months ago
- Enumerate Microsoft service access from a refresh token☆25Apr 1, 2026Updated 5 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- ☆28Nov 25, 2024Updated last year
- Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IO…☆149Apr 13, 2026Updated 4 months ago
- IP address filter by City☆12Jan 17, 2025Updated last year
- A public collection of detections designed to detect threats associated with the Okta WIC Platform.☆34Aug 25, 2026Updated last week
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 4 months ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆335Feb 26, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆22Jan 31, 2023Updated 3 years ago
- A class validation and transformation library, to ensure secure data structures in Python.☆10May 16, 2024Updated 2 years ago
- A basic Intrusion Detection and Prevention System (IDPS) designed to monitor various activities on a host system, detect suspicious beha…☆22Apr 21, 2023Updated 3 years ago
- ☆22Aug 16, 2025Updated last year
- Oracle Attacks Tool☆13Aug 9, 2016Updated 10 years ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.☆23May 27, 2025Updated last year
- The Azure Hyper-V Lab makes virtualization on Azure effortless, perfect for experimenting, learning, and building proof-of-concepts.☆15Updated this week
- AWS services enumerator for penetration testing☆21Nov 11, 2025Updated 9 months ago
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆31Aug 4, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automate Checkmarx Scanning and Onboarding Plus AWS Access☆12Jan 5, 2023Updated 3 years ago
- Threat Hunting Malware Infrastructure☆12Dec 3, 2023Updated 2 years ago
- MISP Playbooks☆234Oct 14, 2025Updated 10 months ago
- Burp plugin that clusters responses to show an overview of received responses☆14Jun 7, 2019Updated 7 years ago
- Basic raw packet sniffer in Python - Cybrary☆12Nov 21, 2017Updated 8 years ago
- A Python-Based script designed to output stable and screen-scrapable lists of wireless networks☆15Jun 19, 2014Updated 12 years ago
- This will be the repo for the BTHb.☆37Jul 27, 2026Updated last month
- Python tool for searching and downloading files from anonymous cloud storage buckets indexed by GrayHat Warfare☆56Mar 5, 2026Updated 6 months ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A preconfigured Velociraptor triage collector☆78Aug 10, 2026Updated 3 weeks ago
- ☆12Oct 9, 2022Updated 3 years ago
- Script to check for CVE-2023-36884 hardening☆15Jul 18, 2023Updated 3 years ago
- Repo for experimenting and testing MCP server builds for CTI-related research.☆27May 13, 2025Updated last year
- ☆24Aug 31, 2026Updated last week
- ☆21Jul 29, 2025Updated last year
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 9 months ago