Skip to content
View mym0us3r's full-sized avatar

Block or report mym0us3r

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mym0us3r/README.md

Hi, I'm m0us3r!

Senior Threat Detection & Research - There is no anonymity on the attack surface, only delays!


whoami

I build and break detection pipelines for a living. My work sits at the intersection of Detection Engineering, Threat Hunting, DFIR, and SIEM/XDR architecture - writing the rules that catch the things generic configs miss, then trying to defeat them myself before someone else does. Wazuh Ambassador, contributing production-tested rulesets, adversarial simulation reports, and native Windows telemetry research to the community. I also run a personal honeypot/SOC lab on Splunk - building dashboards, SPL queries, and alerting from live attack traffic (geo-mapped attacker origins, service/port interaction analysis, user-agent fingerprinting) to keep detection instincts sharp outside of production work. When things go wrong despite it all, Incident Response is where I close the loop.


$ cat /etc/focus/areas

Blue Team Operations · Threat Intelligence · Threat Hunting · Adversary Simulation · Honeypot Research · DFIR · Incident Response · External Attack Surface Management (EASM) · SOC Automation · Detection Engineering · SIEM/XDR (Wazuh · Splunk)


Tech Stack:

Wazuh Splunk Sysmon MITRE ATT&CK Sigma Yara Python Bash PowerShell PHP C++ Windows Linux


GitHub Stats:

GitHub Streak Top Langs

Pinned Loading

  1. Unified-Sysmon-Configs Unified-Sysmon-Configs Public

    Unified Native Sysmon configurations for advanced Windows auditing. Seamless integration with Wazuh SIEM/XDR and other industry-leading SIEM platforms for proactive threat hunting.

    PowerShell

  2. WAZUH-Process-Tree-Viewer WAZUH-Process-Tree-Viewer Public

    A forensic visualization tool for Wazuh that transforms Windows process creation logs (Event ID 4688) into interactive, draggable relationship graphs. Optimized for Threat Hunting and Incident Resp…

    Python 8 3

  3. zion zion Public

    ZION - External Attack Surface Monitor

    Python 30 13

  4. DIRTY-FRAG-Detection-with-Wazuh-4.14.4 DIRTY-FRAG-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

    3

  5. COPY-FAIL-Detection-with-Wazuh-4.14.4 COPY-FAIL-Detection-with-Wazuh-4.14.4 Public

    Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write

    8

  6. Chronogram Chronogram Public

    Advanced Instagram OSINT Tool. Features Tor stealth-routing, obfuscated data recovery, HD media extraction, and automated HTML reporting.

    Python 4