Skip to content
View CRT-3005's full-sized avatar

Block or report CRT-3005

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
CRT-3005/README.md

Callum Thorpe

Junior SOC Analyst with a background in IT operations, infrastructure support, vulnerability management, and Computer Networks. I use this GitHub to document hands-on cybersecurity projects focused on SOC operations, Splunk detection engineering, identity security, Active Directory monitoring, firewall segmentation, and security automation.


Objective

My current focus is to keep developing as a SOC Analyst by building practical projects that improve my skills in:

  • alert triage and investigation
  • Splunk SIEM detection engineering
  • Windows authentication telemetry
  • identity-based threat detection
  • detection tuning and false positive reduction
  • SOC playbooks and response workflows
  • firewall segmentation and lab hardening
  • security automation

This portfolio documents the labs, detections, dashboards, and automation workflows I build to strengthen those skills.


Skills

Skill Associated Project
Splunk Detection Engineering (SPL) Identity Security
Windows Authentication Telemetry (Kerberos / NTLM) Identity Security
Identity Threat Detection & Correlation Identity Security
Detection Tuning & False Positive Reduction Identity Security
SOC Dashboarding & Security Monitoring Identity Security
pfSense Firewall Segmentation & Rule Testing Identity Security
Active Directory Configuration AD-Project
Authentication Attack Simulation AD-Project
SOC Playbook Creation (SOAR) SOAR-EDR
EDR Rule Creation & Detection SOAR-EDR
DevSecOps Automation Pipelines DevSecOps
SAST / DAST / SCA Tooling DevSecOps

Tools

SIEM / Detection Engineering

Endpoint / EDR

Automation

Network / Infrastructure

Adversary Simulation / Attack Emulation

Vulnerability Management / Endpoint Security


Certifications


Current Focus

Recent work has focused on identity threat detection and SOC monitoring, including:

  • writing and tuning Splunk SPL detections
  • correlating Windows authentication events across time and source
  • detecting Kerberos and NTLM password spraying
  • detecting failed-to-successful authentication patterns
  • building authentication and Kerberos security dashboards
  • documenting detections with MITRE ATT&CK mapping
  • creating SOC-style analyst investigation workflows
  • improving lab architecture with pfSense routed segmentation
  • validating firewall rules between attacker, SIEM, and Domain Controller subnets

Projects

Below are the main projects I use to develop and document practical SOC and security engineering skills.


🔐 Identity Security Project

Identity-focused detection engineering project using Splunk, Active Directory, Windows Security telemetry, and pfSense.

The lab focuses on authentication abuse, identity monitoring, detection tuning, hardening validation, and firewall-backed segmentation. It includes:

  • Kerberos and NTLM password spray detections
  • failed-to-successful authentication correlation
  • privileged account authentication monitoring
  • Kerberos security posture dashboarding
  • authentication pressure dashboarding
  • pfSense routed segmentation and firewall rule testing
  • attacker subnet controls for Splunk and Domain Controller access paths
  • MITRE ATT&CK mapping
  • SOC-style investigation workflows and playbooks

🖥️ Active Directory Project

Active Directory lab focused on domain deployment, Windows telemetry collection, Sysmon, authentication attack simulation, and Splunk ingestion.

Key areas covered:

  • Windows Server domain deployment
  • Windows endpoint telemetry
  • Sysmon logging
  • brute force and authentication attack simulation
  • Splunk data ingestion and investigation

🛡️ SOAR & EDR Automation Project

Response automation project using Tines and LimaCharlie to model detection, enrichment, notification, and analyst decision points.

Key areas covered:

  • detection-to-response workflow design
  • endpoint alert enrichment
  • Slack notification workflow
  • analyst approval steps
  • endpoint response actions

⚙️ DevSecOps Pipeline Security

Security testing project focused on SAST, DAST, and SCA scanning against a deliberately vulnerable application.

Key areas covered:

  • static application security testing
  • dynamic application security testing
  • software composition analysis
  • vulnerable application testing
  • pipeline-style security automation

Popular repositories Loading

  1. CRT-3005 CRT-3005 Public

    Config files for my GitHub profile.

  2. AD-Project AD-Project Public

    Active Directory security lab with Windows telemetry, Sysmon, Splunk ingestion, and authentication attack simulation.

  3. SOAR-EDR SOAR-EDR Public

    SOC automation lab using Tines and LimaCharlie for alert enrichment, analyst approval, and endpoint response workflows.

  4. DevSecOps DevSecOps Public

    DevSecOps lab using SAST, DAST, and SCA tooling against vulnerable applications to test security automation workflows.

  5. Identity-Security Identity-Security Public

    Splunk-based identity security lab covering AD authentication telemetry, Kerberos/NTLM detections, dashboards, playbooks, and pfSense segmentation.