Skip to content
View HariCipher's full-sized avatar

Highlights

  • Pro

Block or report HariCipher

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HariCipher/README.md
HariCipher — SOC · DFIR · Detection Engineering

Typing SVG

HariCipher@web ~ $ whoami

HariCipher — ASCII spider HariCipher — role, stack, focus

3rd-year CS student who spends his nights in Splunk instead of on rooftops.
Four months in a real SOC pulling apart Bandook RAT and TrickBot traffic, writing the detections nobody else wanted to tune, and learning that the alert everybody ignores is the one that matters.

HariCipher@web ~ $ arsenal

Splunk Wazuh Wireshark tshark

Python Bash Kali EVTX

MITRE Shuffle OpenCanary VMware

HariCipher@web ~ $ cat case-files/*

CASE-001 · TRACEX — Windows Event Log Analyzer

Caught in the web: a false positive nobody had noticed — service account noise firing a privilege-escalation rule. Found it, fixed it, kept the detection.

Cross-platform EVTX analyser in Python with 5 correlated rules (brute force, LOLBin execution, privilege-escalation sequencing, alternate credential use, account modification), tested against 28,000+ real events on Windows 11 and Kali. Confidence scoring, MITRE ATT&CK mapping, SQLite persistence, interactive HTML dashboard — no SIEM required.

→ HariCipher/tracex

CASE-002 · Bandook RAT — C2 Traffic Analysis

Caught in the web: dual C2 infrastructure that DNS-only monitoring missed entirely — a hardcoded IP reached out 37 minutes before any DNS activity.

Full IOC extraction and ATT&CK mapping across T1071, T1571, T1573, T1568.

→ HariCipher/bandook-c2-traffic-analysis

CASE-003 · Home SOC Lab

Caught in the web: a real SSH credential attempt against the honeypot — logged, detected, and written up end to end.

Splunk + Wazuh SOC lab on Kali and VMware Workstation, with an OpenCanary honeypot in a segmented DMZ isolated via iptables (TCP 6591). Detections built for brute force and lateral movement.

→ HariCipher/Home-Soc-Lab

CASE-004 · Splunk Detection Engineering

Caught in the web: PowerShell execution, failed auth, account creation and service installation — all validated against real Windows telemetry, not synthetic samples.

Documented SPL queries with MITRE mapping for every rule.

→ HariCipher/Splunk-Detection-engineering

HariCipher@web ~ $ tail -f the-web-of-signals


HariCipher@web ~ $ cat threat-board

SOC Analyst Training
Gardiyan System Security Technologies · Turkey (remote)
Sep 2025 – Jan 2026
TryHackMe Hackfinity Battle CTF
Rank 265 · 600 pts
2025
B.Tech, Computer Science Engineering
Poornima University, Jaipur
Expected 2028

HariCipher@web ~ $ ls threads/

Portfolio Email Discord

with great logs comes great responsibility

Pinned Loading

  1. Home-Soc-Lab Home-Soc-Lab Public

    Shell 2 1

  2. bandook-c2-traffic-analysis bandook-c2-traffic-analysis Public

    Wireshark analysis of Bandook RAT C2 traffic — IOC extraction, protocol analysis, and detection notes

    4 1

  3. Splunk-Detection-engineering Splunk-Detection-engineering Public

    1

  4. tracex tracex Public

    Python 1

  5. HoneyPot-Network-Segmentation-Lab HoneyPot-Network-Segmentation-Lab Public

    Shell 1

  6. JitAccess JitAccess Public

    Just-in-time privileged access broker for Linux hosts - request, approve, auto-expire. Kills standing sudo.

    Go 1