A 30-day hands-on SOC Analyst project simulating real-world cyber attacks using ELK Stack, Mythic C2, osTicket & Elastic Defend. Covers threat detection, log analysis, incident response, and cloud-based SOC setup to bridge academic theory with practical cybersecurity skills.
☆45Jun 10, 2025Updated last year
Alternatives and similar repositories for 30-Day-SOC-Analyst-Challenge
Users that are interested in 30-Day-SOC-Analyst-Challenge are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 9 months ago
- ☆62Jun 18, 2025Updated last year
- Comprehensive SOC Analyst notes covering incident response, threat hunting, SOC workflows, and cybersecurity concepts—perfect for exam pr…☆141Feb 26, 2026Updated 5 months ago
- MISP to Microsoft Defender integration☆18Jul 9, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A specialized environment for crafting, validating, and testing LimaCharlie detection rules☆15Nov 11, 2025Updated 9 months ago
- ☆99Jan 7, 2026Updated 7 months ago
- Enumerate Microsoft service access from a refresh token☆25Apr 1, 2026Updated 4 months ago
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17May 11, 2025Updated last year
- Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IO…☆144Apr 13, 2026Updated 4 months ago
- IP address filter by City☆12Jan 17, 2025Updated last year
- A public collection of detections designed to detect threats associated with the Okta WIC Platform.☆34Aug 5, 2026Updated last week
- Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI — companion to the SANS Ransomware Intell…☆22Apr 15, 2026Updated 4 months ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆335Feb 26, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- ☆10Sep 11, 2021Updated 4 years ago
- Kusto and Log Analytics MCP server help you execute a KQL (Kusto Query Language) query within an AI prompt, analyze, and visualize the da…☆23Aug 3, 2026Updated 2 weeks ago
- A class validation and transformation library, to ensure secure data structures in Python.☆10May 16, 2024Updated 2 years ago
- ☆22Aug 16, 2025Updated last year
- bash script to automate the penetration test☆21Jul 11, 2026Updated last month
- Oracle Attacks Tool☆13Aug 9, 2016Updated 10 years ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.☆22May 27, 2025Updated last year
- The Azure Hyper-V Lab makes virtualization on Azure effortless, perfect for experimenting, learning, and building proof-of-concepts.☆15May 17, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- AWS services enumerator for penetration testing☆21Nov 11, 2025Updated 9 months ago
- yara detection rules for hunting with the threathunting-keywords project☆166May 11, 2025Updated last year
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆31Aug 4, 2025Updated last year
- Automate Checkmarx Scanning and Onboarding Plus AWS Access☆12Jan 5, 2023Updated 3 years ago
- Threat Hunting Malware Infrastructure☆12Dec 3, 2023Updated 2 years ago
- ☆31Jun 18, 2025Updated last year
- MISP Playbooks☆233Oct 14, 2025Updated 10 months ago
- Burp plugin that clusters responses to show an overview of received responses☆14Jun 7, 2019Updated 7 years ago
- Basic raw packet sniffer in Python - Cybrary☆12Nov 21, 2017Updated 8 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Python-Based script designed to output stable and screen-scrapable lists of wireless networks☆15Jun 19, 2014Updated 12 years ago
- This will be the repo for the BTHb.☆37Jul 27, 2026Updated 3 weeks ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated last year
- A preconfigured Velociraptor triage collector☆77Aug 10, 2026Updated last week
- ☆12Oct 9, 2022Updated 3 years ago
- Script to check for CVE-2023-36884 hardening☆15Jul 18, 2023Updated 3 years ago
- Repo for experimenting and testing MCP server builds for CTI-related research.☆27May 13, 2025Updated last year