Skip to content
View jsmith-sec's full-sized avatar

Block or report jsmith-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jsmith-sec/README.md

Joshua Smith

Cybersecurity Analyst · SOC & Detection · CompTIA Security+

Typing SVG

Security+ Location Profile views

LinkedIn Email


>_ whoami

Cybersecurity graduate focused on security operations, detection, and incident response. I learn by building. Each lab below recreates the environment and workflow of a real SOC so I can practice the work itself, standing up SIEMs, writing detections, triaging alerts, and investigating incidents. They span detection engineering, incident response, malware and phishing analysis, and Active Directory attack and defense. I appreciate you stopping by, feel free to reach out!


🛡️ SOC / SIEM Detection Lab

A multi-host home SOC on the Elastic Stack with a Windows + Sysmon endpoint. 7 custom detection rules mapped to MITRE ATT&CK across 6 tactics, each validated against a live simulated attack chain. Includes tuning the Sysmon config to close a real endpoint-telemetry visibility gap, detecting LSASS credential dumping via access-mask analysis, and 4 analyst triage writeups documenting the L1 workflow, building a SOC KPI dashboard, and enhacning of IOC threat intelligence.

jsmith-sec/soc-siem-lab


Home SOC Lab Series

# Lab Focus Repo
1 SOC / SIEM Detection Multi-host ELK + Fleet SIEM, Windows/Sysmon endpoint, 7 custom detections mapped to MITRE ATT&CK soc-siem-lab
2 Incident Response Simulation Full PICERL lifecycle, containment & recovery, chain-of-custody documentation incident-response-lab
3 Web Application Attack SQLi / XSS / brute-force detection, Apache log analysis, Kibana rules web-app-attack-lab
4 Vulnerability Assessment Greenbone/OpenVAS (Docker) deployment, vulnerability scanning, OS fingerprinting vulnerability-assessment-lab
5 Malware Analysis Static/dynamic analysis, IOC extraction, MITRE ATT&CK mapping malware-analysis-lab
6 Phishing Analysis Email & URL analysis, SPF/DKIM/DMARC, IOC & campaign correlation phishing-analysis-lab
7 Active Directory Attack & Defense Attack chain (Kerberoasting to DCSync to pass-the-hash) mapped to Windows Event ID detections active-directory-lab

🛠️ Skills & Tooling

Security Operations

SIEM Threat Detection Detection Engineering Incident Response

Malware Analysis Digital Forensics Phishing Analysis MITRE ATT&CK NIST 800-61

Offensive / Adversary Emulation

Active Directory Kerberos Attacks Privilege Escalation Lateral Movement Pass-the-Hash

Tools & Platforms

Elastic Stack Kibana Sysmon Splunk Nmap Linux Python Docker


skill icons


🎓 Certifications

Security+


🎯 What's Next

2026 Goals

Goal Status
TryHackMe SAL1 (SOC Level 1 certification) in progress
AD lab detection layer (blue-team build-out) in progress
Cloud security lab (detection in the cloud) planned

2027 Goals

Goal Status
CompTIA CySA+ (after enterprise SOC experience) planned

Popular repositories Loading

  1. active-directory-lab active-directory-lab Public

    A full Active Directory attack chain, Kerberoasting to Domain Admin, mapped back to the Windows Event IDs that detect each step.

    1

  2. soc-siem-lab soc-siem-lab Public

    A multi-host home SOC on the Elastic Stack with a Windows + Sysmon endpoint. 7 custom detections mapped to MITRE ATT&CK, catching a simulated attack chain in real time.

  3. incident-response-lab incident-response-lab Public

    A full incident response simulation following the PICERL lifecycle, detection and containment through eradication and recovery, with chain-of-custody documentation.

  4. web-app-attack-lab web-app-attack-lab Public

    Attacking DVWA with SQLi, XSS, and brute force, then detecting it, with Apache logs shipped to Kibana and custom detection rules.

  5. vulnerability-assessment-lab vulnerability-assessment-lab Public

    Deploying Greenbone/OpenVAS via Docker for vulnerability assessment on ARM64, feed management, scanning, OS fingerprinting, and real-world troubleshooting.

  6. malware-analysis-lab malware-analysis-lab Public

    Static and dynamic analysis of RustyStealer, AsyncRAT, and Babuk ransomware in an isolated lab, IOC extraction and capability mapping.