Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
-
Updated
Mar 16, 2026 - HTML
Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
Free self-hosted OSINT investigator's toolkit with an MCP server for Claude Code and Claude Desktop. Eighteen tools in one interface: crypto tracing, phishing fingerprinting, domain intel, Telegram OSINT, IP reputation, email header forensics with LLM scam detection, username enumeration, HIBP breach checks, ransomware victim tracking. AGPL-3.0.
Hands-on SOC analyst portfolio featuring Splunk-based alert triage, phishing investigations, log correlation, MITRE ATT&CK mapping, and incident-response documentation.
Email Header Forensics Lab is a desktop application for inspecting, generating, editing, and analyzing email headers in controlled environments for forensic analysis, security research, and authentication testing.
Curated Blue Team toolkit for defensive cybersecurity: asset discovery, vulnerability management, network monitoring, DFIR, threat intelligence, cryptography, endpoint security and SIEM/log management.
Complete notes, challenge walkthroughs, and 20+ alert investigations for the LetsDefend.io SOC Analyst path. This covers SIEM, phishing analysis, web attack detection, malware triage, threat intelligence and Splunk.
SOC-focused security projects: Sentinel detections for identity (AD, Okta, Entra ID) and malware behavior, a custom Windows EDR, incident response and malware analysis.
Phishing awareness analysis toolkit that detects suspicious email red flags, analyzes phishing indicators, and generates Safe / Suspicious / Malicious verdicts.
Forensic analysis of a targeted phishing campaign, email header tracing, URL sandboxing, and IOC extraction.
A modular python toolkit for automated SOC triage, phishing analysis, threat intelligence, and digital forensics.
Phishing email investigation with full header analysis, link inspection, red-flag detection.
Hands-on cybersecurity labs for SOC monitoring, SIEM detection, Windows log analysis, vulnerability assessment, Python automation, and GRC documentation.
Phishing email analysis, header forensics, and IoC extraction for SOC Incident Response workflows.
Comprehensive phishing incident response simulation with email forensics, threat intelligence enrichment, and NIST-aligned playbook
Phishing triage analysis of a real Sneaky2FA AiTM campaign targeting Microsoft 365. Documents the full attack chain, IOC extraction, evasion techniques, and sandbox vs reputation tool detection gap.
Network traffic analysis and phishing investigation project focused on TCP SYN scan detection, threat analysis, and cybersecurity incident identification.
A Python tool to parse .eml email headers, extract embedded URLs, and evaluate phishing threat indicators.
Hands on analysis and defending against phishing emails. Investigating real-world phishing attempts using a variety of techniques.
Phishing email triage and indicator extraction: header consistency, brand impersonation, delivery path, attachment hashing and defanged IOCs, as Markdown or JSON.
To associate your repository with the phishing-analysis topic, visit your repo's landing page and select "manage topics."