Skip to content
View joshuagodwin7929's full-sized avatar

Block or report joshuagodwin7929

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
joshuagodwin7929/README.md

Detection Engineering | SOC | AD Security

I'm an early-career security professional building real, working detection engineering skills, not just watching tutorials. I run my own Active Directory lab, attack it, defend it, and write up what actually happens.

Core Stack

SIEM & Detection

Elastic Kibana KQL Sigma

Endpoint & Adversary Emulation

Sysmon Caldera Windows Linux

IR & Frameworks

MITRE ATT&CK Active Directory


About Me

I'm Joshua, working toward a career in the SOC/detection engineering space. This profile is a record of what I've actually built, not a list of what I've read about.

My approach across every project is the same: log first, attack second, hunt third, then formalize. I don't write a detection until I've run the real attack against my own lab and confirmed what it looks like in the telemetry. If something doesn't work or a technique stays undetected, the README says so. I'd rather show an honest gap than a polished lab that hides one.

Certifications: CompTIA Security+ | ISC2 Certified in Cybersecurity (CC) | working toward CompTIA CySA+


Featured Projects

Project What it is
Cybersecurity-Labs The full AD attack/defense lab, five phases from visibility foundation to Golden Ticket persistence
Detection-Engineering Sigma rules built from real attacks, compiled to Elastic/KQL, tuned against false positives
Purple-Team-Automation Caldera-driven emulation validating the Sigma rules above, with an ATT&CK coverage heatmap
Network-Traffic-Analysis Network-layer visibility work and the infrastructure issues behind it
Incident-Response IR playbooks and response workflow documentation

Connect

LinkedIn X

Pinned Loading

  1. Cybersecurity-Labs Cybersecurity-Labs Public

    My homelab documentation, setup guides, and network configs

    1

  2. Detection-Engineering Detection-Engineering Public

    1

  3. Purple-Team-Automation Purple-Team-Automation Public

    Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

    45 11

  4. Network-Traffic-Analysis Network-Traffic-Analysis Public

  5. Incident-Response Incident-Response Public

  6. Windows-Endpoint-Security Windows-Endpoint-Security Public