Skip to content
View heraclescap's full-sized avatar
🎫
🎫

Highlights

  • Pro

Block or report heraclescap

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
heraclescap/README.md

Hey, I'm Martin Caparros 👋

SOC Analyst Apprentice & Perpetual Learner

I work on Security Operations, building detection pipelines and investigating threats across network, endpoint, and intelligence layers. I train on CyberDefenders and BTLO to develop investigation and forensics skills, and on HackTheBox and Root-Me to stay sharp on the offensive side. Currently CompTIA Security+ certified, with BTL1 as the next target.

Skills

Skill Associated Project
SIEM and Detection Rule Engineering sigwaz-cli / sigwaz.com / wazuh-custom-dashboards
Security Automation and SOAR Orchestration shuffle-soc-automation
Threat Intelligence Operations shuffle-soc-automation / CyberDefenders
Incident Case Management shuffle-soc-automation
Network Forensics and Intrusion Analysis CyberDefenders / BTLO / HackTheBox
Memory and Disk Forensics CyberDefenders / BTLO / HackTheBox
Offensive Techniques and CTF Problem Solving HackTheBox / Root-Me

Tools

SIEM

SOAR & Case Management

Detection Engineering & Threat Hunting

Threat Intelligence

Network Analysis

Digital Forensics

Scripting

DevOps

Certifications

Projects

  • sigwaz-cli - A high-precision Sigma-to-Wazuh rule converter built as a robust CLI tool for automated multi-rule batch processing.
  • sigwaz.com - The live web-based version of the SigWaz converter, providing a clean, minimalist React interface for instant in-browser rule translation.
  • shuffle-soc-automation - End-to-end SOC pipeline: Wazuh alert ingestion, multi-source observable enrichment, automated DFIR-IRIS ticketing.
  • wazuh-custom-dashboards - Custom Wazuh dashboards for SOC monitoring and detection coverage analysis.
  • blueteam-writeups - Detailed write-ups and case studies from CyberDefenders, BTLO, and HackTheBox challenges focusing on forensics, threat intelligence, malware analysis, and more.
  • comptia-secplus-sy0-701-notes - Comprehensive study notes and exam preparation materials for CompTIA Security+ (SY0-701).
  • soc-lab - Personal SOC homelab built on ELK 8.19.16 and MISP 2.4 : documentation, configurations, and deployment guides for a self-hosted open source detection stack.

Pinned Loading

  1. blueteam-writeups blueteam-writeups Public

    Writeups Blue Team des challenges effectués sur CyberDefenders, BTLO ou HackTheBox.

    1

  2. soc-lab soc-lab Public

    Homelab SOC construit sur ELK 8.19.16, MISP 2.4, Sysmon et Atomic Red Team : documentation, configurations et guides de déploiement pour une stack full open source.

    1

  3. sigwaz-cli sigwaz-cli Public

    Convert Sigma detection rules to production-ready Wazuh XML. CLI tool with batch processing, ZIP input, field mapping, and config file support.

    Python 3

  4. soc-lab-detection-engineering soc-lab-detection-engineering Public

    1

  5. shuffle-soc-automation shuffle-soc-automation Public

    SOC automation workflows built with the SOAR Shuffle that coordinates actions between Wazuh, DFIR-IRIS, OpenCTI and Cortex.

    1

  6. wazuh-custom-dashboards wazuh-custom-dashboards Public

    Custom Wazuh dashboards for alert monitoring, software hygiene and vulnerability panorama.

    1 1