Skip to content
View yassinSahli's full-sized avatar
πŸ”’
πŸ”’

Block or report yassinSahli

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yassinSahli/README.md

πŸ‘‹ Hi, Yassine SAHLI Here

πŸ›‘οΈ Security Operations Engineer | Incident Responder | Threat Hunter

πŸŽ“ Security of Computer Systems & Networks Engineering Degree | Network Security Bachelor Degree

πŸ”΅ Blue Team Specialist focused on Detection Engineering, SOC Operations & Infrastructure Security Hardening

πŸ”₯ Ranked TOP #10 on TryHackMe Tunisia Leader board (All-Time 2024) β€” TryHackMe Profile


πŸš€ About Me

Cybersecurity & Infrastructure Security Engineer passionate about building resilient, attack-ready, and automated enterprise environments.

I specialize in:

  • πŸ›‘οΈ Security Operations & Detection Engineering
  • ⚑ Incident Response & Threat Hunting
  • 🧠 Digital Forensics & Malware Analysis
  • πŸ” Linux Infrastructure Hardening & Patch Automation
  • ☁️ Secure Containerized & Air-Gapped Architectures
  • πŸ“‘ Network Security Engineering & Traffic Analysis
  • πŸ€– Security Automation, SOAR & SIEM Engineering

Currently working on large-scale infrastructure security projects involving:

  • Enterprise Linux patch orchestration with Ansible OS specific Roles.
  • SentinelOne EDR deployment & ISO27001 compliance operations.
  • Air-gapped container platforms Integration such as Harbor, Portainer, Cosign, Trivy Scanner (Aqua-DB)..
  • Light-LDAP/LDAPS Authentication Architectures
  • Detection engineering with Wazuh, Splunk, ELK Stack, LimaCharlie and more..
  • SOC automation using TheHive, Cortex, MISP & Ansible playbooks and roles, n8n workflows and more..

I enjoy combining the mindset of an attacker with the discipline of a defender to engineer secure-by-design systems.


πŸ† Professional Certifications

  • πŸ•΅οΈ INE Certified Digital Forensics Professional (eCDFP) β€” Credential
  • 🎯 INE Certified Threat Hunting Professional (eCTHP) β€” Credential
  • 🚨 INE Certified Incident Responder (eCIR) β€” Credential
  • πŸ›‘οΈ INE Security Operations Certified (eSOC) β€” Credential
  • 🧱 INE Certified Enterprise Defender (eEDA) β€” Credential
  • πŸ‘Ύ INE eLearnSecurity Junior Penetration Tester (eJPTv2) β€” Credential
  • πŸ’£ CyberWarFare Certified Red Team Analyst (CRTA) β€” Credential
  • ☒️ TryHackMe Junior Penetration Tester (PT1) β€” Credential
  • πŸ”΄ Red Hat Certified Engineer (RHCE) β€” Credential
  • πŸ”’ Red Hat Certified System Administrator (RHCSA) β€” Credential
  • ☁️ Microsoft Certified: Azure AI Fundamentals (AI-900) β€” Credential
  • 🌐 15x Cisco Certifications β€” Credly Profile
  • πŸ”­ IBM Cybersecurity Analyst Professional Certificate β€” Credential

βš™οΈ Security Projects & Labs

🧠 Unified Threat Detection & Automated SOC Platform

Designed and deployed an enterprise-grade SOC platform integrating:

  • Wazuh SIEM
  • Suricata NIDS
  • FortiGate NGFW
  • TheHive + Cortex + MISP
  • CheckMK Monitoring
  • OpenAudit CMDB
  • Ansible Patch Automation
  • n8n SOAR Workflows
  • GPT-assisted IOC enrichment pipelines

πŸ” Simulated full attack lifecycle detection, enrichment, correlation & automated response workflows inside a Proxmox VE environment.


🎯 Sliver C2 Detection Engineering Lab

Engineered custom detection logic targeting Sliver C2 implants using:

  • LimaCharlie Detection Rules
  • YARA Signatures
  • Windows Process Telemetry
  • Behavioral IOC Correlation

⚑ Achieved sub-60-second detection timing in controlled lab environments.


🧰 Technical Stack

πŸ”΅ Security Operations & SIEM

Wazuh Splunk ELK Stack TheHive Cortex MISP SentinelOne

🌐 Network Security

FortiGate pfSense Suricata Zeek Snort Wireshark

🧠 DFIR & Threat Hunting

Autopsy Volatility FTK YARA Sysmon LimaCharlie

βš™οΈ Automation & Infrastructure

Ansible Docker Podman Linux Bash Python PowerShell

☁️ Cloud & DevSecOps

AWS GCP Harbor Cosign Trivy GitHub Actions


πŸ“ˆ Current Focus

  • Detection Engineering
  • Threat Hunting
  • Linux Infrastructure Security
  • SOC Automation
  • Secure Enterprise Architecture
  • Air-Gapped Security Engineering
  • DFIR & Malware Analysis

🌍 Connect With Me


β€œAlways engineering. Always improving. Always securing.”

Popular repositories Loading

  1. CRTA-Practice-Lab CRTA-Practice-Lab Public

    The primary objective of this Red Team Operation is to assess the security posture of the enterprise environment. The engagement aims to identify vulnerabilities, and misconfigurations in the AD en…

    9 2

  2. RHCSA RHCSA Public

    Everything you need to succeed in the Red Hat Certified System Adminitrator Exam.

    7 1

  3. eJPTv2 eJPTv2 Public

    Everything you need to succeed in the eJPTv2 Practical Exam

    7

  4. Yassine_Sahli Yassine_Sahli Public

    Config files for my GitHub profile.

    3

  5. MoGo_Android_Application MoGo_Android_Application Public

    MoGo ToDo App is a mobile application ; developed in Java (Android Studio) which aims to organize the tasks of a user by priority

    Java 3

  6. Python-Automated-Nmap-Scanner- Python-Automated-Nmap-Scanner- Public

    This Nmap Scanner is a network discovery tool that uses raw IP packets in novel ways to determine what hosts are available on the network and many other useful information for pentesters, making it…

    Python 3