Skip to content
View alejandroZ345's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report alejandroZ345

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
alejandroZ345/README.md

Typing SVG

Open to Work


┌──(alejandro㉿sec-ops)-[~]
└─$ whoami --verbose
> Name : Alejandro Zavala Zenteno
> Role : Jr. Cybersecurity Professional & (soon to be) Computational Systems Engineer
> Cert : ISC2 Certified in Cybersecurity (CC) · 2026–2029
> Base : Morelia, Michoacán · Mexico [UTC-6]
> Focus : SOC Operations | Detection Engineering | SIEM/XDR | Observability | IR
> Status : [ Seeking remote security roles · Open to opportunities ]

┌──(alejandro㉿sec-ops)-[~]
└─$ cat featured_projects.md

Cloud-native observability stack for Docker: zero-instrumentation metrics, centralized logs & unified dashboards — orchestrated via a single docker compose up -d.

Highlights:

  • 7-container stack: WordPress + MySQL (monitored app) + Prometheus + Grafana + Loki + Promtail + cAdvisor
  • Three pillars of observability under one pane of glass
  • WSL2-aware PromQL engineering (cgroup namespace workaround)
  • Loki 2.9.8 schema pinning + UID/GID volume collision resolved
  • 3-step incident diagnostic methodology documented

prometheusgrafanalokidocker-composeobservabilitydevops

wazuh-soc-homelab · COMPLETE

Enterprise-grade Wazuh SIEM/XDR + TheHive IRP deployment — 9 phases covering the full SOC pipeline from stack deployment to automated incident response.

Highlights:

  • 5 custom XML detection rules (behavioral TTPs)
  • MITRE ATT&CK mapping across 7 techniques
  • Automated containment (<2s detection-to-block)
  • TheHive v5 integration via custom Python API bridge
  • 5 standardized triage runbooks

wazuhmitre-attackdetection-engineeringthehiveactive-response


┌──(alejandro㉿sec-ops)-[~]
└─$ cat skill_matrix.txt
[ Security Operations ]
SIEM/XDR ██████████░ Wazuh · OpenSearch · Splunk · Elastic Stack · Active response
Detection Eng ████████░░░ XML rules · Behavioral TTPs · Telemetry analysis · Rule tuning
SOC Workflow ███████░░░░ Alert triage · Reporting · Escalation · SOC KPIs · Workbooks & lookups
Threat Hunt ████████░░░ FIM · Auth correlation · Discovery · C2 detection · IDS fundamentals
Incident Resp ████████░░░ TheHive v5 · Triage runbooks · Containment SOPs · EDR basics · Kill chain
Frameworks ████████░░░ MITRE ATT&CK · Cyber Kill Chain · Pyramid of Pain · NIST CSF · ISO 27001
[ Observability / DevOps ]
Metrics ███████░░░░ Prometheus · cAdvisor · PromQL · Custom dashboards
Logging ███████░░░░ Loki · Promtail · LogQL · Centralized pipelines
Visualization ████████░░░ Grafana · OpenSearch Dashboards · KPI engineering
Orchestration ████████░░░ Docker Compose · Multi-container stacks · Service discovery
[ Infrastructure ]
Linux █████████░░ Ubuntu hardening · Debian · Bash scripting · syslog pipelines
Containers ████████░░░ Docker · Docker Compose · WSL2 · IaC credential management
Windows ██████░░░░░ PowerShell · WazuhSvc · AD basics
[ Networking ]
Protocols ███████░░░░ TCP/IP · OSI Model · DNS · SSH · VPN (Sophos)
Hardware ██████░░░░░ Cisco · Ruckus · Switches · Routers
Analysis ██████░░░░░ Wireshark · Nmap · Firewall config · iptables
[ Offensive (lab only) ]
Tools ██████░░░░░ Hydra · Nmap · Nikto · Metasploit · Kali · Reverse shells

┌──(alejandro㉿sec-ops)-[~]
└─$ systemctl status learning.service
● learning.service - Continuous Skill Development
Loaded: loaded (/etc/systemd/system/learning.service; enabled; preset: enabled)
Active: active (running) since Mon 2026-01-01; always
Main PID: 1337 (always_learning)
Status: "Building toward remote SOC Analyst & Detection Engineering roles"
Tasks: 4 (focused)
Memory: 100%
CPU: full-throttle
Active units:
● detection-engineering-lab.target active (expanding custom ruleset)
● docker-observability-phase-4.service active (performance analysis & diagnostics)
● tryhackme-soc-level-1.path active (blue team path in progress)
● english-technical-writing.service active (daily)
Queued for start:
○ comptia-security-plus.target queued
○ blueteam-labs-ctfs.service queued
○ kql-sentinel-fundamentals.service queued

┌──(recruiter㉿interested)-[~]
└─$ cat hire_alejandro.txt
[ Open to ]
• Jr. SOC Analyst (Tier 1 / Tier 2)
• Detection Engineer (Junior)
• Blue Team / Threat Hunter (Junior)
• Security Operations · Observability-adjacent roles
[ Availability ]
• Full-time · Remote-first (worldwide)
• Timezone : America/Mexico_City (UTC-6) — flexible overlap with LATAM / US / EU-early
• Languages : Spanish (native) · English (technical proficient)
• Start date : Immediate · Notice period: none
[ Fastest way to reach me ]
→ LinkedIn DM (usually reply within 24h)
→ See contact badges below

┌──(alejandro㉿sec-ops)-[~]
└─$ cat /etc/motd
"The goal is not to be better than everyone else,
but to be better than you were yesterday."
Building in public · Documenting every step · Failing forward.

[ Stack ]

WazuhTheHivePrometheusGrafanaLokiDockerUbuntuKaliOpenSearchPythonBashMITRE ATT&CK


[ Connect & Profiles ]

LinkedInISC2 CCTryHackMe


Typing SVG

Pinned Loading

  1. wazuh-soc-homelabwazuh-soc-homelabPublic

    Enterprise-grade Wazuh SIEM/XDR + TheHive IRP deployment on WSL2 and Docker: detection engineering, MITRE ATT&CK mapping, automated active response, SOC dashboards & incident case management. Full …

    4

  2. docker-monitoring-stackdocker-monitoring-stackPublic

    Cloud-native observability stack featuring zero-instrumentation metrics and logging for Docker using Prometheus, Loki, and cAdvisor.

    1