{{ p.name }}
{{ p.summary }}
I'm Mahi Al Jaber — I investigate alerts and write the detections that generate them. My work sits where SOC operations meet cloud telemetry: triage, enrichment, escalation and documentation on one side; CloudTrail, IAM and GuardDuty on the other.
I emulate real attacker techniques in a lab I built myself, capture the telemetry they produce, write detections for them, and document the investigation the way a Tier 1 analyst documents a ticket. Everything here links to evidence — nothing is a course completion.
I investigate alerts — and I write the detections that generate them.
Most junior analysts keep two things separate: SOC operations — triage, enrichment, escalation, documentation — and cloud telemetry — CloudTrail, IAM, GuardDuty. My work sits at the intersection.
Each case file I publish follows the same structure: alert → what I checked and why → enrichment → verdict and confidence → escalation summary → recommended tuning. Including the ones I initially got wrong, because that's where the reasoning shows.
{{ p.d }}
Four projects, each with its own architecture, telemetry and detections. Open one for the full write-up — overview, architecture, technologies, features, screenshots and the repository.
{{ p.summary }}
How every project on this page gets built — the same loop a mature SOC runs to make sure a detection fires before an attacker finds the gap first.
{{ ph.d }}
{{ j.d }}
A repository is a claim. The commit history is whether it holds.
Anyone can list a tool on a CV. What a technical reviewer actually wants is the trail underneath it — the environment, the telemetry it produced, the query that caught it, and an honest note about what the query missed. That's what my GitHub is for.
So read it as working notes rather than a shop window: the labs are reproducible, the detections are written out in full, and the limitations are documented in the same README as the results.
Browse the profile →{{ n.d }}
Hiring for a Tier 1 SOC seat, or an internship? I'd like to hear about it.
Remote worldwide, or relocation. I usually reply within a day.
{{ openProject.title }}
{{ par }}
{{ openProject.arch }}
{{ f.d }}
{{ ft.d }}
| Technique | ID | Tactic | Tool | Log source |
|---|---|---|---|---|
| {{ a.technique }} | {{ a.id }} | {{ a.tactic }} | {{ a.tool }} | {{ a.log }} |
{{ q.note }}
{{ q.body }}