Skip to content
View Rootless-Ghost's full-sized avatar
💜
Void Ninja
💜
Void Ninja

Block or report Rootless-Ghost

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Rootless-Ghost/README.md

Rootless-Ghost/RG-Nebula

Typing SVG Typing SVG

Navy Veteran | SOC Analyst | Detection Engineering | Purple Team Path

Chillin

TryHackMe

TryHackMe Badge

TCM Security

Obsidian VMware

About Me

Former Navy Hospital Corpsman transitioning to cybersecurity with real-world combat experience. I bring military discipline, high-pressure decision-making skills, and a systematic approach to threat detection and incident response.

Purple Team & SOC Focus — building both offensive and defensive capabilities
Operating a 22+ VM home lab for attack simulation and detection engineering
Pursuing PSAA → Security+ → PSAP → PJPT → PNPT certification path
TryHackMe Top 1% - 270+ rooms completed Actively seeking SOC Analyst & Purple Team roles

What I Do

Red Team

  • Penetration Testing & Security Research
  • Red team operations & exploitation
  • Active Directory & Windows exploitation
  • Network security & privilege escalation

Blue Team

  • Threat detection & incident response
  • SIEM analysis & log correlation
  • Threat hunting & malware analysis
  • Security monitoring & alerting

Featured Projects

Detection Engineering

YaraForge - YARA Rule Generator & Testing Platform
Build, manage, test, and visualize YARA detection rules with MITRE ATT&CK mapping and a detection dashboard.
Python Flask YARA MITRE ATT&CK Detection Engineering

SnortForge - SnortForge - Snort IDS/IPS Rule Generator — Flask web app with multi-content chaining, Snort 2/3 syntax toggle, rule performance scoring, 12 detection templates, inline help tooltips, PCRE flag checkboxes, HTTP URI/Header matching, rule validation, and .rules file import/export. Dark-themed UI with real-time live preview. v1.2.0. Python Flask Snort IDS/IPS Network Security

SigmaForge - Vendor-Agnostic Sigma Rule Generator Generate, validate, and convert Sigma detection rules to Splunk SPL, Elastic KQL, Elastic EQL, and Sentinel KQL with MITRE ATT&CK mapping, 12 pre-built templates, and rule library. Python Flask Sigma SIEM Detection Engineering

Blue Team Operations

log-analyzer - Security Log Analyzer
Python-based log analysis tool designed for SOC analysts with pattern matching and anomaly detection.
Python Flask SIEM Log Analysis SOC

phishing-analyzer - Phishing Email Analyzer
Email header and content analysis tool for identifying phishing campaigns and malicious indicators.
Python Email Security Phishing Detection Blue Team

security-awareness-training - Security Awareness Platform
Enterprise-style platform with phishing simulations, training modules, and progress tracking.
Python Flask Security Training Phishing Simulation

Threat Intelligence

Threat-intel-dashboard - Threat Intelligence Dashboard
Real-time threat intelligence platform with IOC tracking, feed aggregation, and visual analytics for SOC operations.
HTML JavaScript Threat Intelligence OSINT SOC

Incident Response

SIREN - Security Incident Response Engine & Notation
Professional incident report generator following NIST 800-61 framework with severity scoring, IOC tracking, timeline management, and Markdown/JSON export.
Python Flask NIST 800-61 Incident Response SOC

Wireless Security

Hidden-Rogue-AP-Detector - Rogue Access Point Detector Python-based wireless security tool for detecting unauthorized access points using RSSI signal strength analysis, whitelist management, and active/passive scanning modes. Python Scapy Wireless Security Network Monitoring Rogue AP Detection

Wi-Fi-Probe-Request-Sniffer - Wi-Fi Probe Request Analyzer Captures and analyzes wireless probe requests from nearby devices with SSID extraction, MAC vendor identification, and CSV/JSON export for network visibility and device enumeration. Python Scapy 802.11 Network Security Device Enumeration


Current Focus

  • Studying for PSAA & CompTIA Security+ certifications
  • Building incident response & detection engineering tooling
  • Expanding home lab with Wazuh SIEM & detection engineering tooling

Certifications

In Progress:

  • 🔹 PSAA (Practical Junior Security Awareness Analyst) - Actively studying
  • 🔹 CompTIA Security+ - Scheduled Q2 2026

Certification Roadmap:

PSAA → Security+ → PSAP → PJPT → PAPA → PNPT

Lab Environments

22+ VM Purple Team Lab:

  • Active Directory lab (attack & defense)
  • Snort IDS/IPS network monitoring
  • Web vulnerability testing environment
  • Malware analysis sandbox
  • WiFi penetration testing lab
  • Flipper Zero / Pwnagotchi
  • Wazuh SIEM with Sysmon integration & MITRE ATT&CK-mapped detections (4 agents across Windows/Linux/Kali)

Operating Systems

Kali Linux Windows Ubuntu Debian

Security Tools

Offensive: Burp Suite Nmap Metasploit Hashcat BloodHound CrackMapExec

Defensive: Wireshark Wazuh Splunk Elastic Snort YARA Sysmon

Hardware: Flipper Zero Pwnagotchi

Syntax Eyes

Breaking to Build. Defending to Endure.

image_alt

Pinned Loading

  1. SnortForge SnortForge Public

    Snort IDS/IPS rule generator — Flask web app with inline help tooltips, 12 detection templates, PCRE flag checkboxes, HTTP URI/Header matching, rule validation, and .rules file import/export

    Python 1

  2. YaraForge YaraForge Public

    YARA Rule Generator & Testing Platform — Build, manage, test, and visualize YARA detection rules with MITRE ATT&CK mapping and a detection dashboard. Built with Python/Flask.

    Python 1

  3. SIREN SIREN Public

    Security Incident Response Engine & Notation — Professional incident report generator following NIST 800-61 framework

    Python 1

  4. log-analyzer log-analyzer Public

    Python security log analyzer for SOC analysts

    Python 1

  5. Wi-Fi-Probe-Request-Sniffer Wi-Fi-Probe-Request-Sniffer Public

    A Python-based tool for capturing and analyzing Wi-Fi probe requests from nearby devices. Uses Scapy for packet manipulation and includes features for SSID extraction, MAC address logging, and vend…

    Python 1

  6. SigmaForge SigmaForge Public

    Vendor-Agnostic Sigma Rule Generator — Splunk SPL, Elastic KQL, Elastic EQL, Sentinel KQL

    Python 1