Skip to content
View 0xsabry's full-sized avatar
🔎
investigate
🔎
investigate

Highlights

  • Pro

Block or report 0xsabry

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xsabry/README.md

Mohamed Sabry Hamdan — SOC Analyst & DFIR Specialist

LinkedIn GitHub SOC Portfolio Zero2Aura Email Profile views

Hey, I'm Mohamed

SOC Analyst & DFIR Specialist specializing in security monitoring, proactive threat detection, digital forensics, and security tool engineering. Currently completing intensive SOC & cybersecurity tracks at NTI (Fortinet SecOps) and ITI (Enterprise Network Hardening), working in DFIR at the Digital Egypt Pioneers Initiative (DEPI), and serving as a Cybersecurity Instructor at Zero2Aura.

Core Expertise & Skills

 Security Operations & SIEM / EDR

Wazuh FortiSIEM FortiAnalyzer Splunk Elastic Sentinel Defender Velociraptor

 Threat Intelligence & Detection Engineering

MITRE ATT&CK Sigma Rules STIX 2.1 FortiGuard YARA MISP ThreatScopeX

 Digital Forensics & Incident Response (DFIR)

Volatility Autopsy FTK Imager KAPE EZ Tools Memory Forensics

 Enterprise Network Architecture & Hardening

Cisco Routing & Switching Wireshark Suricata Zeek pfSense SSH Hardening

 Languages, Automation & SecOps

Python Bash PowerShell C/C++ SQL Linux Docker Git

Featured Open-Source Projects

Project Description Stack / Focus
🔍 ThreatScopeX Advanced log intelligence and threat detection engine with 115+ built-in detection rules Python, MITRE ATT&CK, Sigma, STIX 2.1
📑 IR-Report-Generator Browser-based incident response reporting tool supporting 40+ security tool artifacts HTML5, CSS3, JS, MITRE Navigator
🛡️ SOC Lab Project End-to-end enterprise attack simulation, Wazuh detection, and automated IR simulation Wazuh, Sysmon, EventLogs, Ubuntu, PowerShell
🎣 Phishing IR Framework Complete 6-phase email forensic investigation framework aligned with NIST 800-61 Email Header Forensics, IOC Extraction

Experience & Internships

  National Telecommunication Institute (NTI) | SOC Analyst Intern (FortiAnalyzer + FortiSIEM) | August 2026 – Present
• Completing intensive SOC Analyst track focused on Fortinet Security Operations workflows: event examination, event handlers, automated playbooks, forensic analysis, and threat intelligence reporting.
• Using FortiAnalyzer for log collection and analysis, FortiView searches, incident management, threat hunting, custom reports, and Incident Response playbook creation and monitoring.
• Operating FortiSIEM for real-time and historic searches, event correlation, custom incident rules, dashboard configuration, and UEBA-based threat hunting with FortiGuard Threat Intelligence.
• Practicing detection, analysis, and remediation of security incidents using traditional and AI/ML-assisted methods; preparing for FCP – Security Operations and NSE 6 FortiSIEM Analyst certifications.

  Information Technology Institute (ITI) | Cybersecurity Intern | April 2026 – Present
• Engineered and hardened multi-zone enterprise network architecture in Cisco Packet Tracer with multi-VLAN Layer 2/3 segmentation, dynamic DHCP, and multi-area OSPF routing for secure high-availability communication.
• Designed and enforced Extended ACLs to control traffic flow, isolate wireless zones, and restrict management-plane and server access to authorized hosts.
• Hardened network appliances by enforcing cryptographic SSH on VTY lines and restricting management access; successfully defended architecture before ITI evaluation panel.
• Completed modules in Cyber Security Essentials, Ethical Hacking & Vulnerability Assessment, and Huawei HCCDA Tech Essentials (cloud computing and ICT infrastructure).

  Digital Egypt Pioneers Initiative (DEPI) | Digital Forensics Investigator | Jan 2025 – Present
• Conducting digital forensics examinations, artifact analysis, and memory/disk investigation.

  Zero2Aura Tech Academy | Cybersecurity Instructor | Oct 2025 – Present
• Training students and aspiring security analysts in Cybersecurity, DFIR, Penetration Testing, and Networking.

  Digital Egypt Pioneers Initiative (DEPI) | Cyber Security Incident Response Analyst | Oct 2024 – May 2025
• Analyzed security alerts, mapped incidents to MITRE ATT&CK, and executed IR playbooks.

  The British University in Egypt (BUE) | Cyber Security Intern | Jul 2024

GitHub Analytics & Streak

GitHub Stats GitHub Streak

Thanks for visiting!

Popular repositories Loading

  1. wazuh-shuffle-soar-soc-lab wazuh-shuffle-soar-soc-lab Public

    Enterprise Distributed Open-Source SOC & SOAR Lab: Automated Threat Detection & Incident Response with Wazuh SIEM, Shuffle SOAR, Tailscale Zero-Trust Mesh, and VirusTotal Intel.

    Batchfile 2

  2. ThreatScopeX ThreatScopeX Public

    Advanced Log Intelligence & Threat Detection Engine - 115+ rules, 97 MITRE ATT&CK techniques, STIX 2.1 export, Sigma support, CLI + GUI

    Python 1

  3. IR-Report-Generator IR-Report-Generator Public

    Incident Response Report Platform - Aggregate 40+ security tool findings (SIEM, EDR, IDS, WAF) into professional IR reports with MITRE ATT&CK mapping

    HTML

  4. 0xsabry 0xsabry Public

    My GitHub Profile - SOC Analyst, DFIR, 10 Certifications, 14K+ LinkedIn Followers, Security Tool Developer

  5. Zakarni Zakarni Public

    Forked from refa3ydev-dotNet/Zakarni

    C#

  6. soc-lab-project soc-lab-project Public

    SOC lab portfolio: automated threat detection and incident response with Wazuh, ThreatScope, and MITRE ATT&CK.

    HTML