Skip to content
View malaika-azhar's full-sized avatar

Highlights

  • Pro

Block or report malaika-azhar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
malaika-azhar/README.md

πŸ‘©β€πŸ’» About

BSCS student (Virtual University of Pakistan, 2027) targeting SOC Analyst and Blue Team roles.

During my Blue Team internship I built a working detection setup: Wazuh SIEM, Suricata IDS, a pfSense firewall and live threat intelligence feeds. Every project in my repositories is backed by screenshot evidence, including the failed attempts.


πŸ… Certifications

I earned the Certified Ethical Hacker (C|EH) credential from EC-Council in September 2026. It sits alongside Cisco's Introduction to Cybersecurity and IBM's Cybersecurity Fundamentals. The credential can be checked on EC-Council's verification page with the certificate number below.

Certified Ethical Hacker (C|EH) - EC-Council

Certified Ethical Hacker (C|EH) Β· EC-Council Β· September 2026 Β· Certificate No. ECC7025643981 Β· Verify credential β†’

Cisco IBM


πŸ“ˆ Internship Results

Results from my 12-week Blue Team internship: I documented every week in a report, loaded a URLhaus feed of 20,000+ malicious URLs into Wazuh, and mapped detections across 6 MITRE ATT&CK tactics. After patching openssh on a monitored endpoint, I re-scanned to confirm the findings on that package dropped from 30 to 6.

Reports Feed MITRE CVE


🧱 Lab Architecture

My lab is built around a Wazuh Manager that collects events from an Ubuntu server, a Windows host, a Suricata IDS on Kali Linux and a pfSense firewall. Threat intelligence from URLhaus and VirusTotal is added on top, and the alerts end up on a SOC dashboard.

%%{init: {'theme': 'base', 'themeVariables': {'fontSize': '13px'}, 'flowchart': {'nodeSpacing': 18, 'rankSpacing': 30, 'padding': 8}}}%%
flowchart LR
    subgraph SRC["Log Sources"]
        UA["🐧 Ubuntu agent"]:::src
        WA["πŸͺŸ Windows agent"]:::src
        SU["πŸ”Ž Suricata IDS<br/>(Kali)"]:::src
        PF["πŸ”₯ pfSense firewall<br/>(syslog)"]:::src
    end
    subgraph TI["Threat Intelligence"]
        UH["URLhaus feed"]:::ti
        VT["VirusTotal"]:::ti
        AT["MITRE ATT&CK"]:::ti
    end
    UA --> WM
    WA --> WM
    SU --> WM
    PF --> WM
    UH --> WM
    VT --> WM
    AT --> WM
    WM["πŸ›‘οΈ Wazuh Manager<br/>custom rules + FIM"]:::core --> DB["πŸ“Š SOC Dashboard<br/>alerts + reports"]:::out
    classDef src fill:#1A5276,stroke:#0B2E43,stroke-width:2px,color:#FFFFFF
    classDef ti fill:#5B2C6F,stroke:#3B1A48,stroke-width:2px,color:#FFFFFF
    classDef core fill:#943126,stroke:#571C16,stroke-width:2px,color:#FFFFFF
    classDef out fill:#1E8449,stroke:#0B4F2A,stroke-width:2px,color:#FFFFFF
Loading

Network Map

All lab machines sit in one internal network behind the pfSense firewall.

Lab network map: Internet, pfSense firewall and internal lab network

πŸ” Detection Evidence

Screenshots from my Wazuh lab: custom rules, File Integrity Monitoring and a SOC dashboard.

Custom Wazuh rule 100001 firing on new user creation
Custom rule 100001: alert fires when a new Linux user account is created
Wazuh File Integrity Monitoring alerts for a test file
File Integrity Monitoring: file added, modified and deleted events detected
SOC dashboard alert timeline in Wazuh
SOC dashboard: alert volume over time, built in Wazuh

πŸ§ͺ Featured Projects

Cisco Networking Lab Portfolio
VLANs, OSPF/EIGRP, ACLs, IPsec VPN, port security
Cybersecurity Lab Projects
SOC, SIEM triage, DFIR, malware analysis, threat mapping
Real-World Tier-2 Support Projects
osTicket helpdesk on Azure, SPF/DKIM/DMARC audit, Wireshark fault analysis
Customer Technical Support Portfolio
Ticket simulations, troubleshooting flowcharts, solution guides, escalation scripts

πŸ—“οΈ Journey

I started with Cisco networking labs, moved into Blue Team work during my internship, and closed this period with the CEH certification and my first open source pull request.

%%{init: {'theme': 'base', 'themeVariables': {'fontSize': '15px'}}}%%
timeline
    2026 Feb to May : Cyber Security Training : Cisco labs
    2026 Jun to Sep : Blue Team Internship : Wazuh, Suricata, DFIR
    2026 Sep : CEH certified : Open source pull request
Loading

Cybersecurity Intern, Blue Team Β· Cyberster Β· Jun 2026 to Sep 2026

  • Deployed a Wazuh SIEM with File Integrity Monitoring and custom detection rules on Ubuntu and Windows endpoints.
  • Wrote and tested Suricata IDS rules, and integrated the alerts into Wazuh.
  • Added threat intelligence feeds (VirusTotal, URLhaus, MITRE ATT&CK) to the SIEM.
  • Did malware analysis and digital forensics: disk imaging, Prefetch, registry and timeline correlation.

πŸ› οΈ Skills

My main focus is SIEM monitoring, detection rules and digital forensics, supported by networking and firewall knowledge.

Tech stack icons



Wazuh Suricata pfSense Splunk Wireshark Kali Cisco MITRE

Area Tools and topics
SIEM and detection Wazuh, Suricata, Splunk, MITRE ATT&CK, D3FEND
Forensics and malware Autopsy, Sleuth Kit, Prefetch, registry, ANY.RUN, VirusTotal
Network security pfSense, Cisco IOS, Wireshark, ACLs, VPN

🀝 Open Source

Uptime Kuma

Pull request to Uptime Kuma fixing drag-and-drop of monitors out of a group hierarchy.


🎯 Career Goal

I am looking for a SOC Analyst (Blue Team) or Network/NOC Engineer role where I can keep building detection and investigation skills on real systems.


πŸ“¬ Contact

LinkedIn Β· malaikawork21@gmail.com

Pinned Loading

  1. Cisco-Networking-Lab-Portfolio Cisco-Networking-Lab-Portfolio Public

    Malaika Azhar | Network & Security Engineer Β· IT Support Β· Cybersecurity Β· SOC Operations

  2. Cybersecurity-Lab-Projects Cybersecurity-Lab-Projects Public

    Hands-on cybersecurity portfolio: 10 foundational projects, a 12-week Blue Team internship, and 18 advanced SOC and forensics labs, covering Wazuh SIEM, Suricata IDS, pfSense, Wireshark, malware an…

    Python

  3. Real-World-Tier2-Support-Projects Real-World-Tier2-Support-Projects Public

    4 hands-on Tier-2 IT support projects: osTicket on Azure, email security audit, Wireshark case studies, and an Uptime Kuma bug fix.