Skip to content
View negrete-8's full-sized avatar

    Block or report negrete-8

    Block user

    Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

    You must be logged in to block users.

    Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
    Report abuse

    Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

    Report abuse
    negrete-8/README.md

    Jorge Negrete 🛡️

    Cybersecurity Analyst · Threat Intelligence · Honeypot Operator

    MalwareBazaarThreatFoxVirusTotalAbuseIPDB


    🚀 About

    I run live honeypot infrastructure that captures real-world malware, which I reverse, analyse and report to public threat intelligence feeds. My work covers the full loop — capturing and dissecting Linux malware, building detection with Wazuh, and documenting offensive techniques through hands-on writeups.

    Focus: malware analysis · detection engineering · honeypot operations


    🛠️ Skills

    Programming

    PythonBashSQLYAML

    Operating Systems

    DebianUbuntuKali LinuxWindows

    Malware Analysis & Forensics

    Static AnalysisReverse EngineeringVolatilityIOC ExtractionMITRE ATT&CKYARA

    Blue Team & Honeypot

    WazuhCowrieSIEMIncident ResponseiptablesOPNsense

    Offensive Security

    NmapGobusterOWASP ZAPPrivilege EscalationWiresharkOWASP Top 10

    DevSecOps & Infrastructure

    DockerVagrantGitHub ActionsSnykSonarCloudGitleaks

    Certifications

    Fortinet NSE3Google CybersecurityFCF


    🔥 Featured Work

    RepositoryDescription
    threat-intelligenceMalware analysis reports and structured IOCs from honeypot captures.
    honeypotMulti-service honeypot with attacker scoring and automated C2 fetching.
    wazuh-edr-deploymentWazuh EDR deployment with automated active response.
    pentest-writeupsFull-chain Linux compromise writeups with root cause analysis.
    linux-hardening-labVagrant lab: hardened SSH alongside a Cowrie honeypot.
    devsecops-pipelineCI/CD pipeline with Gitleaks, Snyk, SonarCloud and OWASP ZAP.

    Pinned Loading

    1. threat-intelligencethreat-intelligencePublic

      Malware samples and IOCs captured from honeypots and reported to MalwareBazaar, ThreatFox and VirusTotal

      1

    2. honeypothoneypotPublic

      Multi-service honeypot with attacker scoring and C2 enumeration

      Python 1

    3. devsecops-pipelinedevsecops-pipelinePublic

      CI/CD pipeline with automated security scanning: Gitleaks, Snyk, SonarCloud and OWASP ZAP

      Python 1

    4. security-scriptssecurity-scriptsPublic

      OSINT and recon scripts: Nmap automation, web scraping and web spidering

      Python 1