Skip to content
View geoccifer's full-sized avatar

Block or report geoccifer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

How to design, build, and operate AI agents for infrastructure teams — safely. 13 chapters covering architecture, sandboxing, credentials, change control, observability, and more.

195 21 Updated Jul 30, 2026

A project for hunting detection resistant threat activity using ML. It has been proven and battle tested at great scale and is finding threat activity undetected by major name commercial security p…

Jupyter Notebook 8 3 Updated Aug 12, 2026

DevOps Interview Questions

1,381 241 Updated Mar 10, 2026

SOCAutomators Substack blog companion — threat research, DBIR analysis, and security operations content

20 2 Updated Jun 3, 2026

Provides situational awareness of Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks in support of network security assessments. #nsacyber

Java 1,059 320 Updated Feb 24, 2020

Collection of KQL queries

1,645 381 Updated Jan 29, 2026

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Python 321 35 Updated May 14, 2026

Learn DevSecOps and Cloud Security Engineering fundamentals.

TypeScript 121 30 Updated Aug 14, 2026

Sample playbooks for the Palo Alto Networks Ansible modules.

Jinja 153 61 Updated Apr 1, 2025

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers…

C# 4,625 328 Updated Aug 14, 2026

List of books, blogs, newsletters and people!

7,185 875 Updated May 6, 2026

If you want to become good at AI engineering & system design, join this newsletter 👇

27,764 3,591 Updated Aug 14, 2026

Automated threat intel feed parsing and consolidation💻👾🤖

Python 42 11 Updated Aug 15, 2026

Cyber Threat Intelligence Data, Indicators, and Analysis

114 19 Updated Aug 3, 2026

MCP Server for Wazuh SIEM

Rust 233 59 Updated Dec 12, 2025
Jupyter Notebook 8,912 1,777 Updated Sep 22, 2024

PowerShell tools to help defenders hunt smarter, hunt harder.

PowerShell 488 55 Updated Oct 29, 2025

Collection of Cyber Threat Intelligence sources from the deep and dark web

7,147 1,202 Updated Aug 14, 2026

A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset

Python 42 19 Updated Jun 8, 2020

WSUS Unauthenticated RCE

Python 174 22 Updated Oct 28, 2025

A hands-on Detection Engineering lab for building a full Detection-as-Code pipeline. This project uses Stratus Red Team to simulate attacks in AWS, with custom Sigma rules automatically deployed to…

HCL 3 1 Updated Sep 29, 2025

Scan MCP servers for potential threats & security findings.

Python 1,032 133 Updated Aug 14, 2026

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Jupyter Notebook 822 115 Updated Aug 14, 2026

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

PowerShell 1,334 168 Updated Apr 9, 2026

Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

942 180 Updated Dec 12, 2023

This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, …

18,399 2,086 Updated Mar 14, 2026
Next