Hello, I'm Ghaliah
Dedicated to proactive defense in an evolving threat landscape. Secure. Resilient. Ready.

Whoami
As a Computer Science graduate passionate about defensive cybersecurity, I transitioned from understanding how technology is built to mastering how it is defended. My expertise is focused on Blue Team operations, threat detection, and incident response.
Armed with specialized security certifications and hands-on experience in analyzing network traffic and configuring SIEM environments, I am dedicated to decoding complex data into proactive, resilient defenses that protect critical infrastructure.
Featured Projects
Wazuh SIEM Lab
This project demonstrates an enterprise-grade SIEM setup bridging defensive monitoring with active execution. It features a centralized Wazuh manager on Ubuntu Server orchestrating endpoint agents across both Linux and Windows environments. Built to handle real-world scenarios, the lab integrates File Integrity Monitoring (FIM) to trace unauthorized system alterations, while leveraging the VirusTotal API to continuously cross-reference hashes against global threat intelligence. Upon validating a malicious file, an integrated active response script automatically isolates or purges the threat, feeding detailed telemetry back to dynamic alerts and dashboards mapped directly against the MITRE ATT&CK framework.

Network Traffic Analyzer
Designed to address the critical need for objective, high-speed network reconnaissance triage, this tool automates deep packet analysis without the need for manual Wireshark filtering. Leveraging Python and the Scapy library, it handles core parsing through rdpcap() to break down live or captured traffic. The analyzer isolates network reconnaissance by tracking SYN packet thresholds for port scan detection, identifies web-layer threats via suspicious path matching, and monitors potential data exfiltration through DNS query length baselining. All findings are structured instantly into automated text report files to streamline incident response workflows.

Log & Brute Force Analyzer
Built to simulate real-world security monitoring, this utility automates log parsing to spot critical authentication anomalies. The tool uses a dual-component design: a simulation engine that generates activity logs with a mix of normal access and malicious traffic, and an analytics core that continuously scans the telemetry. By analyzing failed login patterns and tracking threshold spikes from suspicious IP addresses, it distinguishes legitimate user friction from live brute-force attempts. Once a pattern matches, the script bypasses manual inspection to output a clean, defensive report.txt file containing the precise timestamps and threat intelligence needed for immediate triage.

Professional Certifications
CompTIA CySA+
Advanced into tactical blue team operations, continuous monitoring, and security telemetry analysis. Gained hands-on proficiency in leveraging SIEM environments, applying threat intelligence, and managing structured incident response workflows.
Verify CredentialsCompTIA Security+
Validated fundamental expertise in network security, risk mitigation, and infrastructure protection. Established the core cryptographic and access control baselines required to implement proactive security controls across enterprise environments.
Verify CredentialsCourses & Learning
Continuous Growth
Through Learning.
Alongside my academic foundation and core hands-on labs, I consistently expand my technical horizons through specialized industry training. These curated courses sharpen my practical skills in digital defense, cloud architectures, and security automation.
Cybersecurity 101
A foundational hands-on learning path covering essential security methodologies, network concepts, and defensive security environments.
Security Principles in Cloud Computing
An introductory course exploring cloud infrastructure security, shared responsibility models, and identity management.
Automate Cybersecurity Tasks with Python
A practical, development-focused course leveraging Python scripting for security operations and task automation.
Incident Response Analysis — Virtual Work Experience
A simulated professional training experience focused on real-world incident handling, threat mitigation, and security operations.
Skills
Tools I use
Learning Roadmap
- Completed · Step 01
Security Fundamentals
- Completed · Step 02
Linux & OS Fundamentals
- Completed · Step 03
Network Fundamentals
- Completed · Step 04
Security Skills
- Completed · Step 05
Blue Team Projects
- Completed · Step 06
Security+ Certification
- Completed · Step 07
CySA+ Certification
- In Progress · Step 08
SOC L1
Contact Me
Open to entry-level Blue Team, SOC analyst, and incident response opportunities. Reach out through the form or any of the channels below.