Skip to content
View Rootless-Ghost's full-sized avatar
πŸ’œ
Void Ninja
πŸ’œ
Void Ninja

Block or report Rootless-Ghost

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Rootless-Ghost/README.md

Rootless.Ghost/RG.Nebula

Typing SVG

Navy Veteran πŸŽ–οΈ | SOC Analyst | Detection Engineering | Purple Team Path

Chillin

TryHackMe

TryHackMe Badge

TCM Security

Obsidian VMware

πŸŽ–οΈ About Me

Former Navy Hospital Corpsman transitioning to cybersecurity with real-world combat experience. I bring military discipline, high-pressure decision-making skills, and a systematic approach to threat detection and incident response.

πŸ›‘οΈ Purple Team & SOC Focus β€” building both offensive and defensive capabilities
🏠 Operating a 22+ VM home lab for attack simulation and detection engineering
πŸ“š Pursuing PSAA β†’ Security+ β†’ PSAP β†’ PJPT β†’ PNPT certification path
πŸ† TryHackMe Top 1% - 200+ rooms completed 🎯 Actively seeking SOC Analyst & Purple Team roles

🎯 What I Do

Red Team

  • πŸ”“ Penetration Testing & Security Research
  • βš”οΈ Red team operations & exploitation
  • 🏒 Active Directory & Windows exploitation
  • 🌐 Network security & privilege escalation

Blue Team

  • πŸ›‘οΈ Threat detection & incident response
  • πŸ“Š SIEM analysis & log correlation
  • πŸ” Threat hunting & malware analysis
  • 🚨 Security monitoring & alerting

πŸš€ Featured Projects

Detection Engineering

YaraForge - YARA Rule Generator & Testing Platform
Build, manage, test, and visualize YARA detection rules with MITRE ATT&CK mapping and a detection dashboard.
Python Flask YARA MITRE ATT&CK Detection Engineering

SnortForge - Snort IDS/IPS Rule Generator
Flask web app with 12 detection templates, rule validation, and .rules file import/export capabilities.
Python Flask Snort IDS/IPS Network Security

Blue Team Operations

log-analyzer - Security Log Analyzer
Python-based log analysis tool designed for SOC analysts with pattern matching and anomaly detection.
Python Flask SIEM Log Analysis SOC

phishing-analyzer - Phishing Email Analyzer
Email header and content analysis tool for identifying phishing campaigns and malicious indicators.
Python Email Security Phishing Detection Blue Team

security-awareness-training - Security Awareness Platform
Enterprise-style platform with phishing simulations, training modules, and progress tracking.
Python Flask Security Training Phishing Simulation

Threat Intelligence

Threat-intel-dashboard - Threat Intelligence Dashboard
Real-time threat intelligence platform with IOC tracking, feed aggregation, and visual analytics for SOC operations.
HTML JavaScript Threat Intelligence OSINT SOC

Incident Response

SIREN - Security Incident Response Engine & Notation
Professional incident report generator following NIST 800-61 framework with severity scoring, IOC tracking, timeline management, and Markdown/JSON export.
Python Flask NIST 800-61 Incident Response SOC


🎯 Current Focus

  • Studying for PSAA & CompTIA Security+ certifications
  • Building incident response & detection engineering tooling
  • Expanding home lab with ELK Stack SIEM deployment

πŸŽ“ Certifications

In Progress:

  • πŸ”Ή PSAA (Practical Junior Security Awareness Analyst) - Actively studying
  • πŸ”Ή CompTIA Security+ - Scheduled Q2 2026

Certification Roadmap:

PSAA β†’ Security+ β†’ PSAP β†’ PJPT β†’ PNPT

πŸ”¬ Lab Environments

22+ VM Purple Team Lab:

  • Active Directory lab (attack & defense)
  • ELK Stack SIEM deployment & log pipeline
  • Snort IDS/IPS network monitoring
  • Web vulnerability testing environment
  • Malware analysis sandbox
  • WiFi penetration testing lab
  • Flipper Zero / Pwnagotchi

πŸ–₯️ Operating Systems

Kali Linux Windows Ubuntu Debian

πŸ”§ Security Tools

Offensive: Burp Suite Nmap Metasploit Hashcat BloodHound CrackMapExec

Defensive: Wireshark Splunk Elastic Snort YARA Sysmon

Hardware: Flipper Zero Pwnagotchi

Syntax Eyes

Breaking to Build. Defending to Endure.

image_alt

Pinned Loading

  1. SnortForge SnortForge Public

    Snort IDS/IPS rule generator β€” Flask web app with dark theme, 12 detection templates, rule validation, and .rules file import/export

    Python 1

  2. YaraForge YaraForge Public

    YARA Rule Generator & Testing Platform β€” Build, manage, test, and visualize YARA detection rules with MITRE ATT&CK mapping and a detection dashboard. Built with Python/Flask.

    Python 1

  3. SIREN SIREN Public

    Security Incident Response Engine & Notation β€” Professional incident report generator following NIST 800-61 framework

    JavaScript 1

  4. log-analyzer log-analyzer Public

    Python security log analyzer for SOC analysts

    Python 1

  5. security-awareness-training security-awareness-training Public

    Enterprise-style security awareness platform with phishing simulations, training modules, and progress tracking β€” built in Flask.

    Python 1

  6. Threat-intel-dashboard Threat-intel-dashboard Public

    Real-time threat intelligence dashboard with IOC tracking, threat feed aggregation, and visual analytics for SOC operations

    HTML 1