Skip to content
View 0xAtef's full-sized avatar
🥷
I may be slow to respond.
🥷
I may be slow to respond.

Block or report 0xAtef

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xAtef/README.md

🚀 I’m Mohamed Atef

Cyber Defense Lead


📖 About Me

I am a highly skilled Cyber Defense Engineer with a proven track record in leading Security Operations and conducting in-depth assessments of Endpoint Detection & Response (EDR) and Email Security Gateways, Threat Intelligence Platforms (TIP), Attack Surface Management (ASM), Dark Web Monitoring and Digital Risk Protection (DRP), as well as Security Orchestration, Automation, and Response (SOAR) solutions.

My passion lies in designing and optimizing SOC processes, developing robust use cases and incident response playbooks, and implementing advanced detection rules and automation workflows. I also specialize in building custom middleware integrations, ensuring seamless and scalable security operations across diverse environments.

Core Principle:
“You can’t protect what you don’t understand.”


🛡️ Expertise

Area Tools & Technologies
Threat Detection & DFIR SIEM, EDR/XDR, Forensic Toolkits (Velociraptor, KAPE)
SOC Operations & Monitoring SOAR, SIEM, Endpoint Protection (EDR/AV), Azure Monitor Logs
Cyber Threat Intelligence (CTI) MISP, Group-IB (GIB), CTM360
Automation & Orchestration Python, n8n, TheHive, IBM QRadar SOAR, GitHub Actions
Attack Simulation Atomic Red Team, Metasploit Framework, CALDERA, MITRE ATT&CK
Scripting, Integration & Middleware Development Python, syslog, REST APIs, parsing & DSM building
Strategy & Process Design SOC Playbooks, Incident Response Plans, CTI SOPs, SOC SOPs
Attack Surface Management & Digital Risk ASM platforms, DRP services, Dark Web Monitoring tools

🧾 Certificates

  • eCTHPv2 – Certified Threat Hunting Professional (EC-Council)
  • Group-IB – Threat Intelligence Analyst
  • Belkasoft – Windows Forensics Certification

🏆 Key Accomplishments

  • MISP Galaxy “Ransomware Groups”
    Designed and published a custom MISP Galaxy mapping ransomware actors to ATT&CK techniques and metadata.

  • n8n Automation Workflows
    Built end-to-end enrichment pipelines in n8n for MISP events (IoCs, TTPs, victim profiles).

  • MISP Analytics Dashboard
    Created interactive Jupyter Notebook dashboards visualizing events per day, threat categories, and APT actor profiles.

  • Ransomware.live Integration
    Integrated the ransomware.live API into n8n workflows for automated group data enrichment in MISP.

  • MITRE ATT&CK Mapping Automation
    Automated mapping of APT groups to MITRE ATT&CK Intrusion Sets using TAXII feeds and MISP galaxy tags.

  • Security Community Contributions
    Authored multiple blog posts and delivered presentations on MISP best practices and RSS feed integration.

  • External Source Integrations
    Integrated MISP with external intelligence sources: Group-IB (GIB), CTM360.

  • TheHive SOAR Platform Development
    Developed and maintained TheHive for incident response and threat handling; integrated with Cortex, MISP, QRadar, TIP, Digital Risk Protection, email, MS Teams, n8n, and Shuffle to streamline workflows.

  • Security Product Assessments
    Conducted comprehensive evaluations of EDR, Threat Intelligence Platforms, Dark Web Monitoring, Digital Risk Protection, and Attack Surface Management solutions for detection efficacy and integration.

  • Attack Simulation Exercises
    Utilized CALDERA for adversary emulation, running real-world attack scenarios to test and strengthen organizational defenses.

  • Custom SIEM Middleware
    Built middleware to ingest API log data into SIEM platforms, improving log centralization and analysis capabilities.

  • Card Data Discovery Validator
    Created a Python-based tool to validate and mask cardholder data following security compliance standards.

🚀 Featured Projects


📈 GitHub Stats

Profile Views

0xAtef's GitHub Stats 0xAtef's GitHub Streak 0xAtef's Top Languages

📫 Connect with Me



HTTP REST Git GitHub GitLab Bitbucket Visual Studio Code Sublime Text Postman Jupyter Notebook HTML CSS Bootstrap C++ Python Flask MySQL bash Docker Kubernetes AWS Microsoft Azure Elasticsearch Windows Ubuntu fedora Arch Linux

github contribution grid snake animation

Blog posts

Pinned Loading

  1. sigma sigma Public

    Forked from SigmaHQ/sigma

    Main Rule Repository

    Python 1

  2. atomic-red-team atomic-red-team Public

    Forked from redcanaryco/atomic-red-team

    Small and highly portable detection tests based on MITRE's ATT&CK.

    PowerShell