Skip to content
View NATTOMR's full-sized avatar
๐ŸŽฏ
Focusing
๐ŸŽฏ
Focusing

Highlights

  • Pro

Block or report NATTOMR

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
NATTOMR/README.md

Cybersecurity Animated Hero Banner

๐—›๐—ถ, ๐—œ'๐—บ ๐—ก๐—ฎ๐˜๐˜๐—ผ ๐— ๐˜‚๐—ป๐—ถ ๐—–๐—ต๐—ฎ๐—ธ๐—บ๐—ฎ

๐—ฆ๐—ข๐—– & ๐—•๐—น๐˜‚๐—ฒ ๐—ง๐—ฒ๐—ฎ๐—บ ๐—˜๐—ป๐˜๐—ต๐˜‚๐˜€๐—ถ๐—ฎ๐˜€๐˜ | ๐——๐—ฒdication in Blue team field

Building practical cybersecurity projects focused on Threat Detection, Security Operations (SOC), Malware Analysis, and Detection Engineering.

ย 

ย  ย  ย 


๐Ÿš€ ๐—”๐—ฏ๐—ผ๐˜‚๐˜ ๐— ๐—ฒ

I am a Computer Science & Engineering Graduate (2026) and dedicated Cybersecurity & SOC Analyst focused on defensive security, SIEM log analysis, and incident response.

  • ๐Ÿ† ๐—ช๐—ต๐—ฎ๐˜ ๐—œ ๐—›๐—ฎ๐˜ƒ๐—ฒ ๐——๐—ผ๐—ป๐—ฒ โ€” Earned Google Cybersecurity & NPTEL Elite Ethical Hacking (60%, IIT Kharagpur) credentials. Awarded Best Performer at Elevate Labs (Skill India) and built multi-OS Wazuh & Sysmon detection labs.
  • โšก ๐—ช๐—ต๐—ฎ๐˜ ๐—œ ๐—”๐—บ ๐——๐—ผ๐—ถ๐—ป๐—ด ๐—–๐˜‚๐—ฟ๐—ฟ๐—ฒ๐—ป๐˜๐—น๐˜† โ€” Practicing alert triage and incident response on TryHackMe, Hack The Box, and LetsDefend. Writing Python security automation scripts and developing Sigma & YARA detection rules.
  • ๐ŸŽฏ ๐—ช๐—ต๐—ฎ๐˜ ๐—œ๐˜€ ๐— ๐˜† ๐—™๐˜‚๐˜๐˜‚๐—ฟ๐—ฒ ๐—š๐—ผ๐—ฎ๐—น โ€” Targeting Tier-1/Tier-2 SOC Analyst and Security Engineer roles in enterprise defense. Preparing for CompTIA Security+,and BTL1 certifications to advance in detection engineering.

๐ŸŽฏ ๐—–๐˜‚๐—ฟ๐—ฟ๐—ฒ๐—ป๐˜ ๐—™๐—ผ๐—ฐ๐˜‚๐˜€


๐Ÿš€ ๐—™๐—ฒ๐—ฎ๐˜๐˜‚๐—ฟ๐—ฒ๐—ฑ ๐—ฃ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜๐˜€

โž” โž”
โž” โž” โž”

๐Ÿ›ก๏ธ Wazuh SOC Home Lab

End-to-end virtual SOC telemetry environment utilizing Wazuh Manager on Ubuntu Server to monitor Windows 11 endpoint telemetry and Sysmon event logs against simulated MITRE ATT&CK tactics.

๐Ÿ› ๏ธ Tools:ย 

๐Ÿ”— Repository: github.com/NATTOMR/Design-and-Implementation-of-a-Wazuh-Based-SOC-Home-Lab-for-Attack-Detection-and-Log-Analysis

๐Ÿ–ฅ๏ธ Splunk SOC & Threat Hunting Lab

Real-time SOC monitoring lab simulating and correlating brute-force authentication attempts from Kali Linux against an Ubuntu victim using Splunk Enterprise and custom geo-IP dashboards.

๐Ÿ› ๏ธ Tools:ย 

๐Ÿ”— Repository: github.com/NATTOMR/Linux-SSH-Attack-Monitoring-Splunk-SIEM-Lab

๐Ÿค– Android Malware Classifier

Machine-learning-driven mobile security system automating APK static reverse engineering via Androguard and XGBoost / Random Forest classification with >95% benchmark accuracy.

๐Ÿ› ๏ธ Tools:ย 

๐Ÿ”— Repository: github.com/NATTOMR/Android-Malware-Detector--My-Final-Year-Project-2026-

โ˜๏ธ Cloud Security Lab

Hands-on cloud security laboratory covering AWS security, IAM policies, cloud detection, Microsoft Sentinel, cloud SOC architecture, threat hunting, and incident response.

๐Ÿ› ๏ธ Tools:ย 

๐Ÿ”— Repository: github.com/NATTOMR/cloud-security-lab

๐Ÿ“Œ ๐—–๐—ต๐—ฒ๐—ฐ๐—ธ ๐—ผ๐˜‚๐˜ ๐—บ๐˜† ๐—ฝ๐—ถ๐—ป๐—ป๐—ฒ๐—ฑ ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐—ฎ๐—ฏ๐—ผ๐˜ƒ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ณ๐˜‚๐—น๐—น ๐—ฝ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜ ๐—ฑ๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป, ๐—น๐—ฎ๐—ฏ ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ, ๐—ฎ๐—ป๐—ฑ ๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ ๐—ฐ๐—ผ๐—ฑ๐—ฒ!


๐Ÿ›ก๏ธ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† & ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—ฐ๐—ฎ๐—น ๐—ง๐—ผ๐—ผ๐—น๐—ธ๐—ถ๐˜

๐Ÿ›ก๏ธ SIEM & SOC
Wazuh
Wazuh
Splunk
Splunk
TheHive
TheHive
MISP
MISP
โ˜๏ธ Cloud Security
AWS
AWS
Azure
Azure
Sentinel
Sentinel
AWS IAM
AWS IAM
CloudTrail
CloudTrail
๐ŸŒ Network Security
Wireshark
Wireshark
Snort
Snort
Nmap
Nmap
Suricata
Suricata
๐ŸŽฏ Web Security
Burp Suite
Burp Suite
Postman
Postman
๐Ÿ” Threat Detection & Intel
Sysmon
Sysmon
YARA
YARA
MITRE ATT&CK
MITRE ATT&CK
๐Ÿ–ฅ๏ธ Operating Systems
Kali Linux
Kali Linux
Linux
Linux
Ubuntu
Ubuntu
Windows
Windows
๐Ÿ’ป Web Tools & DevOps
Python
Python
Bash
Bash
C
C
C++
C++
FastAPI
FastAPI
React
React
TypeScript
TypeScript
Tailwind
Tailwind
MongoDB
MongoDB
Docker
Docker
Git
Git
GitHub
GitHub
Actions
Actions
VS Code
VS Code

๐Ÿ“Š ๐—š๐—ถ๐˜๐—›๐˜‚๐—ฏ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜๐—ถ๐—ฐ๐˜€

A comprehensive overview of my open-source contributions, language distribution, and daily development activity.

๐Ÿ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ถ๐—ฏ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต ๐—”๐—ป๐—ถ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป

GitHub Contribution Snake


๐Ÿ“š ๐—–๐˜‚๐—ฟ๐—ฟ๐—ฒ๐—ป๐˜๐—น๐˜† ๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด

๐Ÿ›ก๏ธ ๐—•๐—น๐˜‚๐—ฒ ๐—ง๐—ฒ๐—ฎ๐—บ ๐—ข๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€

๐ŸŽฏ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—›๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ย โ€ขย  โšก ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ย โ€ขย  ๐Ÿ“‹ ๐—ฆ๐—ข๐—– ๐—ช๐—ผ๐—ฟ๐—ธ๐—ณ๐—น๐—ผ๐˜„๐˜€ & ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ๐˜€ ย โ€ขย  ๐Ÿšจ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ

๐Ÿ”ฌ ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต

๐Ÿ”ฌ ๐—ฅ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฒ ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ย โ€ขย  ๐Ÿ” ๐—ฆ๐˜๐—ฎ๐˜๐—ถ๐—ฐ & ๐——๐˜†๐—ป๐—ฎ๐—บ๐—ถ๐—ฐ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ ย โ€ขย  ๐Ÿ’ป ๐—•๐—ถ๐—ป๐—ฎ๐—ฟ๐˜† ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ ย โ€ขย  ๐Ÿงฌ ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—•๐—ฒ๐—ต๐—ฎ๐˜ƒ๐—ถ๐—ผ๐—ฟ ๐—ฃ๐—ฟ๐—ผ๐—ณ๐—ถ๐—น๐—ถ๐—ป๐—ด

โ˜๏ธ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†

โ˜๏ธ ๐—”๐—ช๐—ฆ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—™๐˜‚๐—ป๐—ฑ๐—ฎ๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐—น๐˜€ ย โ€ขย  ๐Ÿ”‘ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—œ๐—”๐—  ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ย โ€ขย  ๐Ÿ“Š ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—Ÿ๐—ผ๐—ด๐—ด๐—ถ๐—ป๐—ด & ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป
๐Ÿ›ก๏ธ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ฆ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ฒ๐—น ย โ€ขย  ๐Ÿ—๏ธ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ข๐—– ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ย โ€ขย  โšก ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป & ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ


๐Ÿ“… ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ ๐—ฅ๐—ผ๐—ฎ๐—ฑ๐—บ๐—ฎ๐—ฝ & ๐— ๐—ถ๐—น๐—ฒ๐˜€๐˜๐—ผ๐—ป๐—ฒ๐˜€

  • โœ… ๐—ช๐—ฎ๐˜‡๐˜‚๐—ต ๐—ฆ๐—ข๐—– ๐—›๐—ผ๐—บ๐—ฒ ๐—Ÿ๐—ฎ๐—ฏ โ€” Implemented SIEM server, client log monitoring, and active response rule triggers.
  • โœ… ๐—”๐—ป๐—ฑ๐—ฟ๐—ผ๐—ถ๐—ฑ ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—–๐—น๐—ฎ๐˜€๐˜€๐—ถ๐—ณ๐—ถ๐—ฒ๐—ฟ โ€” Engineered static analysis parser and machine learning classification pipeline.
  • โšก ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด โ€” In Progress: Writing custom Sigma rules and Snort/Suricata signatures for common network/system exploits.
  • โšก ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—›๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด โ€” In Progress: Analyzing artifact behavior using Sysmon logs, Event Viewer, and memory dumps.
  • โšก ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—Ÿ๐—ฎ๐—ฏ โ€” In Progress: Hands-on AWS security, IAM, CloudTrail/CloudWatch logging, and Microsoft Sentinel detection. ย 
  • ๐ŸŽฏ ๐—˜๐—ป๐˜๐—ฟ๐˜†-๐—Ÿ๐—ฒ๐˜ƒ๐—ฒ๐—น ๐—ฆ๐—ข๐—– ๐—ฅ๐—ผ๐—น๐—ฒ โ€” Target: Secure an internship or associate SOC Analyst position to contribute to defensive security.

โšก ๐—–๐—ผ๐—ฟ๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฒ๐˜๐—ฒ๐—ป๐—ฐ๐—ถ๐—ฒ๐˜€

  • ๐Ÿ›ก๏ธ ๐—ฆ๐—œ๐—˜๐—  & ๐— ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ป๐—ด โ€” Log aggregation, rule customisation, dashboard creation (Wazuh, Splunk).
  • ๐Ÿ” ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ & ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป โ€” Sigma rule mapping, MITRE ATT&CK mapping, endpoint visibility.
  • ๐ŸŒ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† โ€” Traffic capture, packet analysis, Intrusion Detection Systems (Wireshark, Suricata).
  • ๐Ÿ”ฌ ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ โ€” Static APK unpacking, code pattern identification, ML behavior models.
  • โ˜๏ธ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† (๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด & ๐—Ÿ๐—ฎ๐—ฏ๐˜€) โ€” AWS (IAM, CloudTrail, CloudWatch), Microsoft Sentinel, KQL, cloud threat detection & Cloud SOC architecture.
  • ๐Ÿ–ฅ๏ธ ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€ ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป โ€” Linux terminal operations, bash automation, Windows server basic configuration.

โญ ๐—ง๐—ต๐—ฎ๐—ป๐—ธ ๐˜†๐—ผ๐˜‚ ๐—ณ๐—ผ๐—ฟ ๐˜ƒ๐—ถ๐˜€๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—บ๐˜† ๐—ฝ๐—ฟ๐—ผ๐—ณ๐—ถ๐—น๐—ฒ! ๐—œ๐—ณ ๐˜†๐—ผ๐˜‚ ๐—น๐—ถ๐—ธ๐—ฒ ๐—บ๐˜† ๐˜„๐—ผ๐—ฟ๐—ธ, ๐—ฐ๐—ผ๐—ป๐˜€๐—ถ๐—ฑ๐—ฒ๐—ฟ ๐˜€๐˜๐—ฎ๐—ฟ๐—ฟ๐—ถ๐—ป๐—ด ๐—บ๐˜† ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€.

Pinned Loading

  1. Android-Malware-Detector--My-Final-Year-Project-2026- Android-Malware-Detector--My-Final-Year-Project-2026- Public

    A hybrid static and dynamic Android malware analysis platform using machine learning classifiers (Random Forest & XGBoost) with a Next.js frontend.

    Python 4

  2. Design-and-Implementation-of-a-Wazuh-Based-SOC-Home-Lab-for-Attack-Detection-and-Log-Analysis Design-and-Implementation-of-a-Wazuh-Based-SOC-Home-Lab-for-Attack-Detection-and-Log-Analysis Public

    A Wazuh-based Security Operations Center (SOC) Home Lab for attack detection and log analysis using Ubuntu Server, Windows 11, Kali Linux, Sysmon, and VirtualBox.

    Python 3

  3. AI-Assisted-Vulnerability-Scanner AI-Assisted-Vulnerability-Scanner Public

    AI-assisted vulnerability scanning platform for automated security assessment, vulnerability analysis, structured findings, and actionable remediation guidance

    Python 2

  4. Phishing-Attack-Simulation-Detection Phishing-Attack-Simulation-Detection Public template

    A cybersecurity lab project for simulating phishing attacks and analyzing detection techniques, with security awareness, email threat analysis, and defensive monitoring workflows.

    HTML 2

  5. Intelligent-Intrusion-Detection-System-for-Encrypted-Network-Traffic Intelligent-Intrusion-Detection-System-for-Encrypted-Network-Traffic Public

    A Hybrid Intrusion Detection System (IDS) combining XGBoost and PyTorch Autoencoders to detect zero-day cyber attacks in encrypted network traffic without Deep Packet Inspection.

    Python 3

  6. splunk-p1-soc-home-lab splunk-p1-soc-home-lab Public archive

    SOC log monitoring and security analysis project using Splunk for centralized log collection, event analysis, threat detection, investigation, and security reporting.

    Python 2