Skip to content

Latest commit

ย 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

CyberSecurity Study Hubs โ€” Executive Defense & Threat Hunting Architecture

GitHub Pages Live Portal eSOC Live Workspace eCTHP Live Workspace License: MIT Security Posture INE Security

A synchronized, client-side cybersecurity knowledge portal bridging Reactive SOC Operations (Tier-1 / eSOC) and Proactive Enterprise Threat Hunting (eCTHP).


โšก Direct Quick Access & Live Demos

๐ŸŒ Main Executive Portal ๐Ÿ›ก๏ธ eSOC Live Workspace ๐ŸŽฏ eCTHP Live Workspace
Unified Command Center & Matrix Reactive Defense & Incident Triage Proactive Threat Hunting & Forensics
๐Ÿ‘‰ Launch Executive Portal ๐Ÿ‘‰ Launch eSOC Workspace ๐Ÿ‘‰ Launch eCTHP Workspace

๐Ÿ“‘ Table of Contents


๐Ÿ› Executive Overview & Dual Strategy

Modern enterprise cyber defense requires seamless synergy between Reactive Alert Handling and Proactive Adversary Hunting. Relying solely on SIEM alerts creates visibility blind spots, while unfocused hunting without operational baseline telemetry wastes critical analyst hours.


๐Ÿ—บ Architecture & Curriculum Map

1. Security Operations (Reactive Defense โ€” eSOC)

  • Target Certification: INE Security Operations Certified โ€“ Level 1 (eSOC)
  • Curriculum Scope: 10 Comprehensive Courses (76h 57m Total Duration)
  • Primary Operational Focus:
    • Log Analysis & SIEM Operations: Query building in Splunk, Elastic, and KQL; parsing Windows Event Logs (Security, System, Sysmon) and Linux auditd/syslog.
    • Alert Triage & Correlation: Differentiating True Positives from False Positives, noise reduction, and SLA-compliant incident escalation.
    • Malware & Phishing Analysis: Header inspection, SPF/DKIM/DMARC verification, static triage of suspicious attachments, and sandbox analysis.
    • Network Packet Inspection: Deep-packet triage with Wireshark and tcpdump, protocol validation, and TCP stream reassembly.
    • Incident Detection & Response: Applying the NIST SP 800-61 / SANS PICERL framework to contain host breaches and preserve evidence.

2. Threat Hunting (Proactive Adversary Hunting โ€” eCTHP)

  • Target Certification: INE Certified Threat Hunting Professional (eCTHP)
  • Curriculum Scope: 5 Advanced Hunting Modules
  • Primary Operational Focus:
    • Hypothesis Generation: Formulating structured hunts based on threat intelligence reports, environmental anomalies, and MITRE ATT&CKยฎ matrix tactics.
    • Adversary TTP Mapping: Deconstructing threat actors using the Diamond Model of Intrusion Analysis and the Pyramid of Pain.
    • Endpoint Hunting & Memory Volatility: Hunting for process injection (DLL injection, process hollowing, reflective DLL loading), persistence mechanisms, and memory artifacts using Volatility.
    • Network Threat Hunting: Uncovering C2 channels, periodic beaconing, DNS tunneling, JA3/JA3S fingerprint anomalies, and HTTP user-agent outliers.
    • Detection Engineering: Translating successful hunt discoveries into automated Sigma rules, YARA signatures, and SIEM correlation searches.

๐Ÿ“ธ Visual Previews & Workspaces

eSOC Study Hub Live Workspace

Comprehensive interactive dashboard featuring shortcut navigation, per-course deep modules, packet analysis syntax, and log triage decision trees.

eSOC Study Hub Live Workspace Screenshot

๐Ÿ‘‰ Open eSOC Live Workspace (Full Page)


eCTHP Study Hub Live Workspace

Advanced hunting portal providing hypothesis design workflows, memory volatility references, network beacon analysis guides, and persistence checklists.

eCTHP Study Hub Live Workspace Screenshot

๐Ÿ‘‰ Open eCTHP Live Workspace (Full Page)


๐Ÿ“‚ Repository Structure

CyberSecurity-Study-Hubs/
โ”œโ”€โ”€ .gitignore                      # Git exclusion rules (OS, editor, temp files)
โ”œโ”€โ”€ LICENSE                         # MIT License + Dedicated Privacy/Security Notice
โ”œโ”€โ”€ README.md                       # Executive-grade documentation (this file)
โ”œโ”€โ”€ index.html                      # Unified Command Center & Embedded Viewer Portal
โ”œโ”€โ”€ assets/
โ”‚   โ”œโ”€โ”€ css/
โ”‚   โ”‚   โ””โ”€โ”€ portal.css              # Dark cyber glassmorphism styles
โ”‚   โ”œโ”€โ”€ js/
โ”‚   โ”‚   โ””โ”€โ”€ shield.min.js           # Anti-tamper & client-side security shield
โ”‚   โ””โ”€โ”€ images/
โ”‚       โ”œโ”€โ”€ esoc-preview.png        # Actual high-res screenshot of eSOC workspace
โ”‚       โ”œโ”€โ”€ ecthp-preview.png       # Actual high-res screenshot of eCTHP workspace
โ”‚       โ”œโ”€โ”€ esoc-preview.svg        # Scalable vector mockup of eSOC workspace
โ”‚       โ””โ”€โ”€ ecthp-preview.svg       # Scalable vector mockup of eCTHP workspace
โ””โ”€โ”€ hubs/
    โ”œโ”€โ”€ eSOC.html                   # eSOC Study Hub Workspace (1.01 MB)
    โ””โ”€โ”€ eCTHP.html                  # eCTHP Study Hub Workspace (435 KB)

โœจ Core Capabilities & Engineering

  • Zero-Dependency Architecture: 100% native HTML5, modern CSS3, and vanilla JavaScript. Runs anywhere without Node build steps, webpack, or external packages.
  • Embedded Interactive Switcher: The root portal (index.html) embeds both workspaces via responsive iframes with zero scrollbar clipping and fullscreen toggling.
  • High-Contrast Dark Glassmorphism: Engineered with a unified color token system (--bg: #090a0f, --cyan: #22d3ee, --purple: #3b82f6, --green: #4ade80).
  • Offline & Air-Gapped Ready: Can be cloned to a USB drive or air-gapped lab environment and used immediately with any web browser.

๐Ÿš€ How to Access & Run Locally

Option 1: Web Browser Direct (No Setup)

Simply navigate to the live GitHub Pages portal:

Or download the repository and double-click index.html or files in hubs/.

Option 2: Local HTTP Server (Python)

# Clone the repository
git clone https://github.com/TOOSHY2/CyberSecurity-Study-Hubs.git
cd CyberSecurity-Study-Hubs

# Start local server on port 8080
python -m http.server 8080

Browse to http://localhost:8080/.

Option 3: Node.js / npx serve

npx serve .

Option 4: VS Code Live Server

  1. Open the project folder in VS Code.
  2. Right-click index.html (or eSOC.html / eCTHP.html).
  3. Click "Open with Live Server".

โš–๏ธ Academic & Security Disclaimer

Important

Educational & Fair-Use Notice:

  • These study hubs and synthesized notes are independent, personal educational resources developed by the author for certification preparation, professional competence, and technical reference.
  • All certification titles, course frameworks, and curriculum tracks (eSOC, eCTHP) are registered trademarks and intellectual property of INE Security (formerly eLearnSecurity). Full academic credit and attribution are extended to INE Security and their instructional staff.
  • Integrity & Compliance: This repository contains NO proprietary examination questions, leaked test dumps, or confidential evaluation material. All explanations, commands, and workflows represent original syntheses derived from public defensive security documentation and general industry standards.

๐Ÿ“„ License & Credits

  • License: Distributed under the permissive MIT License with an appended Educational & Security Fair-Use rider.
  • Author: Hasan (TOOSHY2)
  • Training Provider: INE Security

About

๐Ÿ›ก๏ธ Executive Cyber Defense & Threat Hunting Study Hubs โ€” Interactive, zero-dependency knowledge portal bridging reactive Tier-1 SOC operations (eSOC) and proactive enterprise threat hunting (eCTHP). Mapped to INE Security curriculums.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Contributors

Languages