A synchronized, client-side cybersecurity knowledge portal bridging Reactive SOC Operations (Tier-1 / eSOC) and Proactive Enterprise Threat Hunting (eCTHP).
| ๐ Main Executive Portal | ๐ก๏ธ eSOC Live Workspace | ๐ฏ eCTHP Live Workspace |
|---|---|---|
| Unified Command Center & Matrix | Reactive Defense & Incident Triage | Proactive Threat Hunting & Forensics |
| ๐ Launch Executive Portal | ๐ Launch eSOC Workspace | ๐ Launch eCTHP Workspace |
- Executive Overview & Dual Strategy
- Architecture & Curriculum Map
- Visual Previews & Workspaces
- Repository Structure
- Core Capabilities & Engineering
- How to Access & Run Locally
- Academic & Security Disclaimer
- License & Credits
Modern enterprise cyber defense requires seamless synergy between Reactive Alert Handling and Proactive Adversary Hunting. Relying solely on SIEM alerts creates visibility blind spots, while unfocused hunting without operational baseline telemetry wastes critical analyst hours.
- Target Certification: INE Security Operations Certified โ Level 1 (
eSOC) - Curriculum Scope: 10 Comprehensive Courses (76h 57m Total Duration)
- Primary Operational Focus:
- Log Analysis & SIEM Operations: Query building in Splunk, Elastic, and KQL; parsing Windows Event Logs (Security, System, Sysmon) and Linux
auditd/syslog. - Alert Triage & Correlation: Differentiating True Positives from False Positives, noise reduction, and SLA-compliant incident escalation.
- Malware & Phishing Analysis: Header inspection, SPF/DKIM/DMARC verification, static triage of suspicious attachments, and sandbox analysis.
- Network Packet Inspection: Deep-packet triage with Wireshark and
tcpdump, protocol validation, and TCP stream reassembly. - Incident Detection & Response: Applying the NIST SP 800-61 / SANS PICERL framework to contain host breaches and preserve evidence.
- Log Analysis & SIEM Operations: Query building in Splunk, Elastic, and KQL; parsing Windows Event Logs (Security, System, Sysmon) and Linux
- Target Certification: INE Certified Threat Hunting Professional (
eCTHP) - Curriculum Scope: 5 Advanced Hunting Modules
- Primary Operational Focus:
- Hypothesis Generation: Formulating structured hunts based on threat intelligence reports, environmental anomalies, and MITRE ATT&CKยฎ matrix tactics.
- Adversary TTP Mapping: Deconstructing threat actors using the Diamond Model of Intrusion Analysis and the Pyramid of Pain.
- Endpoint Hunting & Memory Volatility: Hunting for process injection (DLL injection, process hollowing, reflective DLL loading), persistence mechanisms, and memory artifacts using Volatility.
- Network Threat Hunting: Uncovering C2 channels, periodic beaconing, DNS tunneling, JA3/JA3S fingerprint anomalies, and HTTP user-agent outliers.
- Detection Engineering: Translating successful hunt discoveries into automated Sigma rules, YARA signatures, and SIEM correlation searches.
Comprehensive interactive dashboard featuring shortcut navigation, per-course deep modules, packet analysis syntax, and log triage decision trees.
๐ Open eSOC Live Workspace (Full Page)
Advanced hunting portal providing hypothesis design workflows, memory volatility references, network beacon analysis guides, and persistence checklists.
๐ Open eCTHP Live Workspace (Full Page)
CyberSecurity-Study-Hubs/
โโโ .gitignore # Git exclusion rules (OS, editor, temp files)
โโโ LICENSE # MIT License + Dedicated Privacy/Security Notice
โโโ README.md # Executive-grade documentation (this file)
โโโ index.html # Unified Command Center & Embedded Viewer Portal
โโโ assets/
โ โโโ css/
โ โ โโโ portal.css # Dark cyber glassmorphism styles
โ โโโ js/
โ โ โโโ shield.min.js # Anti-tamper & client-side security shield
โ โโโ images/
โ โโโ esoc-preview.png # Actual high-res screenshot of eSOC workspace
โ โโโ ecthp-preview.png # Actual high-res screenshot of eCTHP workspace
โ โโโ esoc-preview.svg # Scalable vector mockup of eSOC workspace
โ โโโ ecthp-preview.svg # Scalable vector mockup of eCTHP workspace
โโโ hubs/
โโโ eSOC.html # eSOC Study Hub Workspace (1.01 MB)
โโโ eCTHP.html # eCTHP Study Hub Workspace (435 KB)
- Zero-Dependency Architecture: 100% native HTML5, modern CSS3, and vanilla JavaScript. Runs anywhere without Node build steps, webpack, or external packages.
- Embedded Interactive Switcher: The root portal (
index.html) embeds both workspaces via responsive iframes with zero scrollbar clipping and fullscreen toggling. - High-Contrast Dark Glassmorphism: Engineered with a unified color token system (
--bg: #090a0f,--cyan: #22d3ee,--purple: #3b82f6,--green: #4ade80). - Offline & Air-Gapped Ready: Can be cloned to a USB drive or air-gapped lab environment and used immediately with any web browser.
Simply navigate to the live GitHub Pages portal:
- Main Portal: https://tooshy2.github.io/CyberSecurity-Study-Hubs/
- eSOC Hub: https://tooshy2.github.io/CyberSecurity-Study-Hubs/hubs/eSOC.html
- eCTHP Hub: https://tooshy2.github.io/CyberSecurity-Study-Hubs/hubs/eCTHP.html
Or download the repository and double-click index.html or files in hubs/.
# Clone the repository
git clone https://github.com/TOOSHY2/CyberSecurity-Study-Hubs.git
cd CyberSecurity-Study-Hubs
# Start local server on port 8080
python -m http.server 8080Browse to http://localhost:8080/.
npx serve .- Open the project folder in VS Code.
- Right-click
index.html(oreSOC.html/eCTHP.html). - Click "Open with Live Server".
Important
Educational & Fair-Use Notice:
- These study hubs and synthesized notes are independent, personal educational resources developed by the author for certification preparation, professional competence, and technical reference.
- All certification titles, course frameworks, and curriculum tracks (
eSOC,eCTHP) are registered trademarks and intellectual property of INE Security (formerly eLearnSecurity). Full academic credit and attribution are extended to INE Security and their instructional staff. - Integrity & Compliance: This repository contains NO proprietary examination questions, leaked test dumps, or confidential evaluation material. All explanations, commands, and workflows represent original syntheses derived from public defensive security documentation and general industry standards.
- License: Distributed under the permissive MIT License with an appended Educational & Security Fair-Use rider.
- Author: Hasan (TOOSHY2)
- Training Provider: INE Security