Skip to content
View huseynAgazade's full-sized avatar

Block or report huseynAgazade

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
huseynAgazade/README.md

Huseyn Aghazada

Detection & Response Engineer  ·  Senior SOC Analyst (L3) @ MSSP

tagline



experience OSCP CRTO ATT&CK

 🛡️  whoami

I own security incidents end to end — triage, containment, root-cause analysis, remediation, and post-incident review — across endpoint, identity, network, cloud, phishing, and account-compromise cases. Then I automate the parts that shouldn't need a human twice.

My open-source work turns SOC and IR toil into code: SOAR playbooks that ship through CI, detections managed like software, and tooling that shortens an analyst's day.

role:     Senior SOC Analyst (L3) @ MSSP   # escalation point for real intrusions
detect:   ATT&CK threat hunts -> tuned rules in Cortex XSIAM, Splunk ES, Falcon, SentinelOne
automate: Python playbooks in Splunk SOAR & Cortex XSOAR  (agentic + AI-assisted)
dfir:     Volatility, Autopsy, FTK  +  reverse-engineering compiled code when needed

 🚀  Featured work

Project What it does
🧩 detection-as-code Reusable CI/CD pipeline templates for building, testing, validating, and deploying security detections as code.
splunk-soar-mcp MCP server exposing 70 tools for Splunk SOAR — playbooks, containers, artifacts, administration, visual-editor blocks.
🔍 soar-playbook-ci CI for a SOAR playbook repo: structure validation plus a regex + LLM credential scan.
🧬 pycinspect Read, decompile, and patch CPython 3.13 .pyc files — every reconstruction verified against the bytecode.

 📊  Impact, by the numbers

SOAR playbooks SLA compliance MTTD / MTTR Manual toil
150+ 82% → 95% −40–45% −60%

 🎓  Certifications

OSCP CRTO CCFR eCRE eCIR eCPPT eJPT Technion

 🧰  Toolbox

Python Splunk CrowdStrike Elastic Docker Kubernetes GitHub Actions Linux Bash

 📫  Reach me

LinkedIn Medium Email

Pinned Loading

  1. splunk-soar-mcp splunk-soar-mcp Public

    MCP server for Splunk SOAR (Phantom) — 70 tools for playbooks, containers, artifacts, administration and visual-editor blocks.

    Python 2

  2. detection-as-code detection-as-code Public

    Detection-as-Code — Reusable CI/CD pipeline templates and tooling for building, testing, validating, and deploying security detections as code.

    Python 1

  3. soar-playbook-ci soar-playbook-ci Public

    CI for a SOAR playbook repo: structure validation plus a regex + LLM credential scan. GitHub Actions and GitLab CI.

    Python 1

  4. soc-watchfloor soc-watchfloor Public

    HTML 1

  5. splunk-soar-chronos splunk-soar-chronos Public

    Splunk SOAR app that runs playbooks on a schedule without creating containers

    Python 1