Skip to content
View mmrjb's full-sized avatar
  • Open to relocation

Block or report mmrjb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mmrjb/README.md

Hi, I'm Mohammadmahdi Rajabzadeh

Detection Engineer · Threat Hunter · Senior Security Specialist

I am a cybersecurity professional with 6+ years of experience across SOC operations, detection engineering, and Purple Team activities. I focus on turning endpoint, network, and SIEM telemetry into actionable detections and repeatable investigation workflows.

My work includes advanced alert investigation, security use-case development, log-source integration, parser engineering, detection tuning, threat hunting, and adversary-informed validation.

Featured Project

An open-source Linux threat hunting framework designed to support structured, evidence-driven investigations with Velociraptor.

  • 114 custom Velociraptor artifacts
  • 14 investigation domains covering baseline, identity, authentication, processes, network activity, persistence, file activity, privilege escalation, malware, containers, exfiltration, and secrets
  • Master-triage and hypothesis-driven investigation workflow
  • Repository validation with GitHub Actions
  • Versioned artifact pack and implementation documentation

View the repository · Download v0.1.0

Core Expertise

Area Experience
Detection Engineering Detection lifecycle, use-case design, rule tuning, false-positive analysis, and MITRE ATT&CK mapping
Threat Hunting & DFIR Hypothesis-driven hunting, triage, evidence correlation, Linux investigations, and Velociraptor
SOC & SIEM Advanced alert investigation, log-source onboarding, parser development, and operational detection content
Purple Team Adversary simulation support, telemetry validation, detection testing, and coverage improvement
Endpoint & Network Telemetry Windows and Linux logs, Sysmon, EDR/XDR telemetry, Zeek, and network evidence
Automation Python, PowerShell, Bash, Ansible, and CI-based validation workflows

Current Focus

  • Cloud detection engineering with KQL and Microsoft Sentinel
  • Detection-as-Code workflows and CI/CD validation
  • Linux threat hunting and DFIR automation
  • Building practical, documented, and reusable defensive security projects

Open to Opportunities

I am interested in international opportunities as a Detection Engineer, Threat Hunter, Senior SOC Analyst, or Purple Team Specialist, including roles offering relocation support.

I also welcome collaboration on detection engineering, threat hunting, Velociraptor, SIEM content, and open-source defensive security projects.

Pinned Loading

  1. linux-threat-hunting-with-velociraptor linux-threat-hunting-with-velociraptor Public

    A structured Linux threat hunting framework powered by Velociraptor, featuring 114 custom artifacts across 14 investigation domains.

    Python 1