
Wazuh → n8n SOC Pipeline
A real-time alert pipeline that turns raw Wazuh detections into deduplicated, severity-routed notifications — built with n8n so triage doesn't start from a flooded inbox.
I'm Omar Babba, a cybersecurity engineering student focused on detection engineering and threat intelligence. Explore the systems I build, the threats I investigate, and the evidence behind the work.

A real-time alert pipeline that turns raw Wazuh detections into deduplicated, severity-routed notifications — built with n8n so triage doesn't start from a flooded inbox.

A Splunk Cloud lab documenting Windows log ingestion and Sysmon forwarding, with detection searches for brute-force and PowerShell misuse written and tested end-to-end.

Static and dynamic analysis of 5 real malware samples, fully isolated inside a REMnux sandbox — behavior, IOCs, and technique mapping documented for each one.
The August threat intelligence report: accelerated exploitation, ransomware economics, and attacks on critical infrastructure. Events put in context, techniques mapped, and sources cited.
Read the August reportI'm a 4th-year Computer Science & Networks engineering student at EMSI Tanger, focused on defensive security and SOC operations.
I learn by building working detection pipelines, investigating real malware samples in isolated labs, and documenting what holds up under testing. My work spans SIEM engineering, incident response, and a side interest in blockchain security.
I'm looking for a SOC analyst internship where I can bring that hands-on approach to real alerts and learn from an experienced team.
Delivered security fundamentals training and a phishing simulation. Gained exposure to SCADA environments, the Riot platform, and GLPI.
Application security, network monitoring, VPNs, and intrusion detection. Applying the coursework in documented security labs.

Explore the tools and techniques I work with.
SIEM / SOAR · Sigma · MITRE ATT&CK · OCSF · Alert triage · Log analysis
Triage · Containment · Eradication · EVTX · auditd · Zeek
Wireshark · NetFlow · Zabbix · IPsec / IKE · OpenVPN · WireGuard · OSPF
OWASP Top 10 · SQLi / XSS · Access control · APK analysis · Root detection
Solidity · ERC-20 / 721 · Slither · Semgrep · Gitleaks
OSINT collection · Source grading · ATT&CK mapping · CTI reporting