Skip to content
View mym0us3r's full-sized avatar

Block or report mym0us3r

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mym0us3r/README.md

I'm m0us3r - A cybersecurity engineering enthusiast


There is no anonymity on the attack surface, only delays!

My work focuses on Detection Engineering, Threat Hunting, DFIR, and SIEM/XDR architecture - developing behavioral detections from Windows and Linux telemetry, including Sysmon, Windows Security Events, PowerShell, ETW, Linux Audit, and Syslog. I validate detections through adversary simulation and map detection coverage to MITRE ATT&CK and NIST.

As a Wazuh Ambassador and Splunk researcher, I contribute production-tested rulesets, adversarial simulation research, and native telemetry projects that strengthen detection capabilities across the community. I maintain a personal security research lab where I run an active honeypot powered by Splunk - building dashboards, SPL analytics, and investigating live attack traffic through geolocation, service interaction analysis, user-agent fingerprinting, and detection validation.

When prevention and detection aren't enough, Incident Response is where I close the loop - turning every investigation into insights that improve future detections.


Blue Team · Threat Intelligence · Threat Hunting · Adversary Simulation · Honeypot Research
DFIR · Incident Response · EASM · SOC Automation · Detection Engineering · Wazuh · Splunk

Wazuh Sysmon Splunk MITRE Sigma Yara Python PowerShell Bash Windows Linux






Pinned Loading

  1. Unified-Sysmon-Configs Unified-Sysmon-Configs Public

    Unified Native Sysmon configurations for advanced Windows auditing. Seamless integration with Wazuh SIEM/XDR and other industry-leading SIEM platforms for proactive threat hunting.

    PowerShell

  2. WAZUH-Process-Tree-Viewer WAZUH-Process-Tree-Viewer Public

    A forensic visualization tool for Wazuh that transforms Windows process creation logs (Event ID 4688) into interactive, draggable relationship graphs. Optimized for Threat Hunting and Incident Resp…

    HTML 8 3

  3. zion zion Public

    ZION - External Attack Surface Monitor

    Python 30 13

  4. DIRTY-FRAG-Detection-with-Wazuh-4.14.4 DIRTY-FRAG-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

    3

  5. COPY-FAIL-Detection-with-Wazuh-4.14.4 COPY-FAIL-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write

    9

  6. Chronogram Chronogram Public

    Advanced Instagram OSINT Tool. Features Tor stealth-routing, obfuscated data recovery, HD media extraction, and automated HTML reporting.

    Python 5