Skip to content
View KuRo0x's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report KuRo0x

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
KuRo0x/README.md

Walid Ait Zaouit | KuRo

SOC Detection Engineer | Threat Hunting | SIEM | Incident Response

Morocco (UTC+1) | Open to Remote Roles | Available for Night Shifts

Email LinkedIn GitHub

Cybersecurity hero image

About Me

SOC Detection Engineer with hands-on experience designing and operating a self-built virtual SOC lab — covering the full detection lifecycle from raw telemetry ingestion to escalation-ready case documentation.

I work from telemetry to decision: correlating Windows Event Logs and Sysmon data, building MITRE ATT&CK-mapped Sigma rules, validating detection logic against real attacker tooling (Mimikatz, Nmap, Hydra), and producing structured investigation reports. My approach prioritises signal over noise — understanding why an indicator matters, not just that it fired.

  • Design and validate SIEM detection rules (Splunk SPL + Elastic KQL)
  • Investigate Windows endpoint telemetry using structured triage methodology
  • Develop Sigma detection logic aligned to MITRE ATT&CK TTPs
  • Perform threat hunting across log sources for persistence, lateral movement, and execution
  • Conduct malware analysis and digital forensics in isolated lab environments
  • Produce clear, escalation-ready case documentation for remote SOC workflows

SIEM & Detection Stack

Splunk Elastic Stack KQL Sigma MITRE ATT&CK

Sysmon Winlogbeat Filebeat Windows Event Logs


Offensive Tooling (for Detection Validation)

Mimikatz Nmap Hydra Wireshark


Languages & Scripting

tech icons

Python PowerShell Bash SQL


Network & Infrastructure

pfSense TCP/IP IDS/IPS SSH


Certifications

  • Google Cybersecurity Professional Certificate (Coursera)
  • Cybersecurity for Everyone (Coursera)
  • Self-studying toward BTL1 and CySA+

Languages

  • Arabic (Native)
  • French (Professional)
  • English (Professional)

GitHub Analytics

Profile views

Popular repositories Loading

  1. vSOC-Lab vSOC-Lab Public

    A detection-focused Virtual Security Operations Center (vSOC) lab simulating real SOC telemetry ingestion, investigation, and MITRE ATT&CK–aligned detection, including a SOC-validated phishing awar…

    Python 1

  2. SOC-Detection-Lab SOC-Detection-Lab Public

    A detection-focused Virtual SOC lab | ELK · Suricata · Sysmon · Sigma · MITRE ATT&CK | Blue Team Portfolio by KuRo

    1

  3. ctf-writeups ctf-writeups Public

    Cybersecurity CTF writeups and technical analysis from TryHackMe challenges, including enumeration, exploitation steps, tools used, MITRE ATT&CK mapping, and detection opportunities.

    1

  4. KuRo0x KuRo0x Public

  5. Net-Mapper Net-Mapper Public

    Network Discovery & Security Monitoring Tool

    Python

  6. web-app-me web-app-me Public

    HTML