hi Ilyes here. 👋

21 yo SOC analyst from Tunisia 🇹🇳

I turn noisy logs into clear security stories.

For opportunities, connect with me via LinkedIn or email

Ben Arous, Tunisia

Use the portfolio assistant to ask about projects, SOC skills, and contact information.

LinkedInGitHubEmail

Blue-team pathway

experience & credentials

  • FO

    Cybersecurity / CTI Intern

    MISP
    ATT&CK
    Sigma
    KQL
    SPL
    • Developing a CTI-to-detection engineering platform that ingests MISP indicators, normalizes IOCs, maps activity to MITRE ATT&CK, and produces SOC-ready detection use cases.
    • Built analyst workflows for IOC provenance, telemetry readiness, detection gap tracking, and report export.
    • Generated Sigma/KQL/SPL-style detection templates for validation in SIEM workflows.
    • Documented detection logic, evidence requirements, and analyst handoff notes.
  • HA

    Practical SOC Training

    Splunk
    Elastic
    Sysmon
    Sigma
    YARA
    • Investigated simulated SOC cases in Splunk and Elastic by correlating Windows Event Logs, Sysmon activity, network indicators, and command-line artifacts.
    • Reconstructed attack timelines involving suspicious PowerShell execution, C2 traffic, privilege escalation, and Active Directory-related behavior.
    • Performed alert triage, IOC extraction, root-cause analysis, MITRE ATT&CK mapping, and incident reporting.
    • Developed Sigma/YARA detection logic and translated findings into SIEM-oriented queries and analyst handoff notes.
    • Reviewed IDS/IPS and network evidence from Suricata, Snort, Zeek, and PCAPs to validate suspicious traffic patterns.

featured security work

view more
Personal Project

GrantScope — Entra ID OAuth & Service Principal Risk Investigator

Built a cloud identity investigation tool to analyze OAuth applications, service principals, permission grants, app credentials, privileged app-role assignments, owners, sign-in activity, and directory audit events.

  • Designed correlation logic for risky tenant-wide grants, credential changes, missing owners, privileged service principals, suspicious consent, and unusual app usage.
  • Generated analyst-ready case packets with evidence timelines, risk rationale, remediation steps, and handoff notes.
  • Implemented evidence-bundle imports and structured findings into cases, suppressions, and reviewable observations.
Cloud Security
Entra ID
FastAPI
Identity Security
OAuth
PostgreSQL
Service Principals
Personal Project

SignalProof — Telemetry Contract & Detection Validation Platform

Built a contract-driven platform to validate endpoint telemetry, required event fields, detection quality, and detection latency against YAML-defined security testing contracts.

  • Designed an ATT&CK-mapped validation engine for telemetry checks, detection review, and latency tracking.
  • Integrated Wazuh/OpenSearch-style validation to diagnose collection, parsing, ingestion, and detection failures.
  • Developed FastAPI APIs, PostgreSQL persistence, evidence reports, regression comparison, and a Streamlit dashboard.
ATT&CK
Detection Validation
FastAPI
OpenSearch
PostgreSQL
Streamlit
Wazuh
YAML

Independent Security Project

Cyblu

Cyblu is a small blue-team initiative focused on cyber visibility, detection gaps, and first defensive priorities for small organizations.

Security Notes

view more