Skip to content
View mym0us3r's full-sized avatar

Block or report mym0us3r

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mym0us3r/README.md

Hi, I'm m0us3r!

Senior Threat Detection & Research

There is no anonymity on the attack surface, only delays!

whoami

I build and break detection pipelines for a living :)

My work focuses on Detection Engineering, Threat Hunting, Digital Forensics & Incident Response (DFIR), and SIEM/XDR architecture, developing behavioral detections from Windows and Linux telemetry, including Sysmon, Windows Security Events, PowerShell, ETW, Linux Audit, and Syslog. I validate detections through adversary simulation and map detection coverage to frameworks such as MITRE ATT&CK and NIST.

As a Wazuh Ambassador, I contribute production-tested rulesets, adversarial simulation research, and native telemetry projects that help strengthen detection capabilities across the community. Outside production, I maintain a personal SOC and honeypot lab powered by Splunk, where I build dashboards, develop SPL analytics, and investigate live attack traffic through geolocation, service interaction analysis, user-agent fingerprinting, and detection validation. The goal is simple: continuously transform real-world telemetry into better detections.

When prevention and detection aren't enough, Incident Response is where I close the loop. Turning every investigation into insights that improve future detections.


Blue Team Operations · Threat Intelligence · Threat Hunting · Adversary Simulation/Emulation · Honeypot Research · DFIR · Incident Response · External Attack Surface Management (EASM) · SOC Automation · Detection Engineering · Wazuh SIEM/XDR · Splunk Enterprise

Wazuh Splunk Sysmon MITRE ATT&CK Sigma Yara Python Bash PowerShell PHP C++ Windows Linux

Pinned Loading

  1. Unified-Sysmon-Configs Unified-Sysmon-Configs Public

    Unified Native Sysmon configurations for advanced Windows auditing. Seamless integration with Wazuh SIEM/XDR and other industry-leading SIEM platforms for proactive threat hunting.

    PowerShell

  2. WAZUH-Process-Tree-Viewer WAZUH-Process-Tree-Viewer Public

    A forensic visualization tool for Wazuh that transforms Windows process creation logs (Event ID 4688) into interactive, draggable relationship graphs. Optimized for Threat Hunting and Incident Resp…

    HTML 8 3

  3. zion zion Public

    ZION - External Attack Surface Monitor

    Python 30 13

  4. DIRTY-FRAG-Detection-with-Wazuh-4.14.4 DIRTY-FRAG-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

    3

  5. COPY-FAIL-Detection-with-Wazuh-4.14.4 COPY-FAIL-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write

    9

  6. Chronogram Chronogram Public

    Advanced Instagram OSINT Tool. Features Tor stealth-routing, obfuscated data recovery, HD media extraction, and automated HTML reporting.

    Python 4