Skip to content
View jsmith-sec's full-sized avatar
👾
Locked in
👾
Locked in

Block or report jsmith-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jsmith-sec/README.md

Joshua Smith

Cybersecurity Analyst · SOC & Detection · CompTIA Security+

Typing SVG

Security+ Location Profile views


>_ whoami

Hey, I'm Joshua — a cybersecurity graduate focused on security operations, detection, and incident response. Please take a look around, my SOC lab details are listed below.


🧪 Home SOC Lab Series

# Lab Focus Repo
1 SOC / SIEM Detection ELK Stack SIEM, custom detection rules, real-time alerting soc-siem-lab
2 Incident Response Simulation Full PICERL lifecycle, containment & recovery, chain-of-custody documentation incident-response-lab
3 Web Application Attack SQLi / XSS / brute-force detection, Apache log analysis, Kibana rules web-app-attack-lab
4 Vulnerability Assessment Greenbone/OpenVAS (Docker) deployment, vulnerability scanning, OS fingerprinting vulnerability-assessment-lab
5 Malware Analysis Static/dynamic analysis, IOC extraction, MITRE ATT&CK mapping malware-analysis-lab
6 Phishing Analysis Email & URL analysis, SPF/DKIM/DMARC, IOC & campaign correlation phishing-analysis-lab
7 Active Directory Attack Attack chain (Kerberoasting → DCSync → pass-the-hash) mapped to Windows Event ID detections active-directory-lab

🛠️ Skills & Tooling

Security Operations

SIEM Threat Detection Incident Response Malware Analysis Digital Forensics Phishing Analysis MITRE ATT&CK NIST 800-61

Offensive / Adversary Emulation

Active Directory Kerberos Attacks Privilege Escalation Lateral Movement Pass-the-Hash

Tools & Platforms

Splunk Wireshark Linux Python Docker AWS Azure


skill icons

🎓 Certifications

Security+

Popular repositories Loading

  1. soc-siem-lab soc-siem-lab Public

    A home SOC built on the ELK Stack — deploying a SIEM, writing custom detection rules, and catching simulated attacks in real time.

  2. incident-response-lab incident-response-lab Public

    A full incident response simulation following the PICERL lifecycle — detection and containment through eradication and recovery, with chain-of-custody documentation.

  3. web-app-attack-lab web-app-attack-lab Public

    Attacking DVWA with SQLi, XSS, and brute force — then detecting it, with Apache logs shipped to Kibana and custom detection rules.

  4. vulnerability-assessment-lab vulnerability-assessment-lab Public

    Deploying Greenbone/OpenVAS via Docker for vulnerability assessment on ARM64 — feed management, scanning, OS fingerprinting, and real-world troubleshooting.

  5. malware-analysis-lab malware-analysis-lab Public

    Static and dynamic analysis of RustyStealer, AsyncRAT, and Babuk ransomware in an isolated lab — IOC extraction and capability mapping.

  6. jsmith-sec jsmith-sec Public

    Cybersecurity graduate | CompTIA Security+ | 7-lab Home SOC series spanning blue-team detection and offensive Active Directory attacks