Mahi Al Jaber — SOC Analyst · Detection & Response
About Toolchain Projects Phases Journey GitHub Contact
Open to entry-level SOC roles & internships

Detection.
Response.
Evidence.

{{ rotLine }}

I'm Mahi Al Jaber — I investigate alerts and write the detections that generate them. My work sits where SOC operations meet cloud telemetry: triage, enrichment, escalation and documentation on one side; CloudTrail, IAM and GuardDuty on the other.

I emulate real attacker techniques in a lab I built myself, capture the telemetry they produce, write detections for them, and document the investigation the way a Tier 1 analyst documents a ticket. Everything here links to evidence — nothing is a course completion.

Mahi Al Jaber
Spec sheet
{{ row.k }}
{{ row.v }}
01

What I do

I investigate alerts — and I write the detections that generate them.

Most junior analysts keep two things separate: SOC operations — triage, enrichment, escalation, documentation — and cloud telemetry — CloudTrail, IAM, GuardDuty. My work sits at the intersection.

Each case file I publish follows the same structure: alert → what I checked and why → enrichment → verdict and confidence → escalation summary → recommended tuning. Including the ones I initially got wrong, because that's where the reasoning shows.

Alert triage Detection engineering Threat hunting Adversary emulation Cloud security
{{ p.n }}

{{ p.t }}

{{ p.d }}

02

Toolchain

Hands-on, in a lab I built

{{ g.group }}

{{ g.idx }}
{{ it }}
03

Case files

Four projects, each with its own architecture, telemetry and detections. Open one for the full write-up — overview, architecture, technologies, features, screenshots and the repository.

{{ p.kicker }} {{ p.status }}

{{ p.name }}

{{ p.summary }}

{{ t }}
Open case file → {{ p.repoLabel }}
04

Project phase

How every project on this page gets built — the same loop a mature SOC runs to make sure a detection fires before an attacker finds the gap first.

{{ ph.n }} {{ ph.tag }}

{{ ph.t }}

{{ ph.d }}

  • {{ i }}
05

Learning journey

{{ j.stage }}
{{ j.state }}

{{ j.t }}

{{ j.d }}

06

GitHub

@mahialjaber →

A repository is a claim. The commit history is whether it holds.

Anyone can list a tool on a CV. What a technical reviewer actually wants is the trail underneath it — the environment, the telemetry it produced, the query that caught it, and an honest note about what the query missed. That's what my GitHub is for.

So read it as working notes rather than a shop window: the labs are reproducible, the detections are written out in full, and the limitations are documented in the same README as the results.

Browse the profile →
{{ n.n }}

{{ n.t }}

{{ n.d }}

07

Get in touch

Hiring for a Tier 1 SOC seat, or an internship? I'd like to hear about it.

Remote worldwide, or relocation. I usually reply within a day.

Send a message

POST /API/CONTACT
{{ errors.name }}
{{ errors.email }}
{{ errors.message }} {{ charCount }}
Validated client-side, then again on the API.
{{ notice.title }}

{{ notice.body }}

Open in mail client →
Mahi Al Jaber — Blue Team BUILT FROM THE REPOS · GITHUB.COM/MAHIALJABER
{{ openProject.kicker }}

{{ openProject.name }}

{{ openProject.title }}

Overview

{{ par }}

Architecture & workflow

{{ openProject.arch }}
{{ f.t }}

{{ f.d }}

Technologies

{{ t }}

Features

{{ ft.t }}

{{ ft.d }}

MITRE ATT&CK mapping

TechniqueIDTacticToolLog source
{{ a.technique }} {{ a.id }} {{ a.tactic }} {{ a.tool }} {{ a.log }}

{{ openProject.codeLabel }}

{{ q.label }}

{{ q.note }}

{{ q.body }}

Screenshots

{{ s }}
Repository → Live demo → {{ openProject.demoNote }}