Skip to content
View 0xAtef's full-sized avatar
πŸ₯·
I may be slow to respond.
πŸ₯·
I may be slow to respond.

Block or report 0xAtef

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xAtef/README.md

πŸš€ Cyber Defense Lead


πŸ‘¨β€πŸ’» About Me

user@0xAtef:~$ whoami
> Mohamed Atef

user@0xAtef:~$ role
> Cyber Defense Lead | Blue Team Strategist

user@0xAtef:~$ mission
> Orchestrating next-gen SOC operations, architecting resilient defense ecosystems, and engineering automated threat response.

user@0xAtef:~$ core_competencies
> CTI, Detection-as-Code, Threat Hunting, Adversary Emulation, SOAR Architecture

user@0xAtef:~$ current_status
> Leading high-performance defense teams & driving security maturity.

user@0xAtef:~$ executing
> ./threat_hunting.sh --target=advanced_persistent_threats --mode=continuous

πŸ› οΈ Technology Stack

πŸ›‘οΈ SIEM & Log Management

QRadar Splunk Elastic FortiSIEM

πŸ€– SOAR & Automation

TheHive n8n Shuffle IBM Resilient Python

πŸ” EDR, XDR & NDR

Trellix Fidelis Group-IB IBM QNI

🧠 Threat Intelligence (TIP) & Dark Web

MISP ThreatQ Dark Atlas CTM360 SOC Radar

βš”οΈ C2 & Emulation

Covenant Havoc Caldera


πŸ’Ό Professional Journey

2025 - Present | Cyber Defense Lead

Leading MSSP security operations, strategy, and team development.

  • Strategic Leadership: Architecting high-velocity security operations and cultivating elite engineering talent to drive continuous defensive innovation.
  • Security Architecture & Engineering: Leading end-to-end SOC deployments and transforming legacy environments through Maturity Assessments and Gap Analysis. Expert implementation of multi-vendor ecosystems including FortiSIEM, QRadar, TheHive, ELK, Wazuh, MISP, and SOAR pipelines (n8n, Shuffle).
  • Crisis Management & DFIR: Directing high-stakes incident response engagements for advanced persistent threats, orchestrating containment and eradication strategies for Ransomware, Bootkits, and BEC campaigns.

2024 - 2025 | Sr. Cyber Defense DFIR Analyst

Leading CTI operations, threat hunting, and detection engineering.

  • Threat Detection: Champion a Detection-as-Code philosophy using CI/CD pipelines for detection logic.
  • Intelligence Operations: Operationalize intelligence via MISP with real-time SIEM integration.
  • Automation Architecture: Design and maintain "ThreatOps" and other custom automation tools.

2022 - 2024 | Sr. SOC/Cyber Defense Analyst

SOC operations, SIEM/SOAR administration, security architecture.

2021 - 2022 | Security Operations Specialist

Incident response, security monitoring, and compliance.


πŸ† Key Accomplishments

  • πŸ€– Automated CTI Pipeline: Built comprehensive automated CTI pipeline using MISP, N8n, and Python.
  • πŸ—ΊοΈ MISP Galaxy: Designed and published a custom MISP Galaxy mapping ransomware actors to ATT&CK.
  • πŸ”„ n8n Workflows: Built end-to-end enrichment pipelines for MISP events.
  • πŸ“Š MISP Analytics: Created interactive Jupyter Notebook dashboards for threat visualization.
  • βš”οΈ Attack Simulation: Utilized CALDERA for adversary emulation and defense testing.

🧾 Certificates

  • πŸŽ“ eCTHPv2 – Certified Threat Hunting Professional (EC-Council)
  • πŸŽ“ Group-IB – Threat Intelligence Analyst
  • πŸŽ“ Group-IB – Cyber Crime Investigator
  • πŸŽ“ Belkasoft – Windows Forensics Certification

πŸš€ Featured Projects


πŸ“ˆ GitHub Stats

0xAtef's GitHub Stats 0xAtef's GitHub Streak 0xAtef's Top Languages

github contribution grid snake animation

Blog posts

Popular repositories Loading

  1. sigma sigma Public

    Forked from SigmaHQ/sigma

    Main Rule Repository

    Python 1

  2. 0xAtef 0xAtef Public

  3. atomic-red-team atomic-red-team Public

    Forked from redcanaryco/atomic-red-team

    Small and highly portable detection tests based on MITRE's ATT&CK.

    PowerShell

  4. sigma-specification sigma-specification Public

    Forked from SigmaHQ/sigma-specification

    Sigma rule specification

  5. C2-Server C2-Server Public

    Forked from 0xRick/c2

    A basic c2 / agent.

    Python

  6. Blue-Team-Notes Blue-Team-Notes Public

    Forked from Purp1eW0lf/Blue-Team-Notes

    You didn't think I'd go and leave the blue team out, right?