Skip to content
View nicky-quist's full-sized avatar

Block or report nicky-quist

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nicky-quist/README.md

Nicholas Quist

SOC / Blue Team — Splunk SPL detections, PCAP/Suricata investigations, IR triage. Student at UNC Wilmington.

I build practical detections, investigate alerts end-to-end, and document the work like a real SOC would: triage → pivot → timeline → IOCs → detection → tuning.

LinkedIn · LetsDefend · Hack The Box


Projects

ProjectWhat it is
soc-triage-toolReact app that triages a pasted alert (syslog, Windows Event, Suricata, Zeek, CEF) — detects the log format, scores severity, and maps it to MITRE ATT&CK. Live demo
splunk-detectionsSPL detections with data requirements, investigation pivots, MITRE mapping, and false-positive tuning notes for each one
llm-cybersecurity-benchmarkHead-to-head benchmark of LLMs on SOC analysis tasks — detection engineering, threat reasoning, IR scenarios. Live dashboard
attack-path-modelerParses Nessus scan data into an attack graph, ranks lateral-movement paths by exploit difficulty, and visualizes it with matplotlib + an interactive D3 dashboard
rmf-security-assessment-sampleA full NIST RMF assessment lifecycle worked end-to-end for a fictional case-management system — categorization through ATO recommendation
windows-event-labsHands-on labs on high-signal Windows Security + Sysmon event IDs, with process/network correlation writeups
pcap-investigationsNetwork investigation case studies — PCAP → IOCs → timeline → SIEM pivots
soc-triage-playbooksAlert triage checklists and escalation thresholds by alert type
nmap-log-analysisRecon-detection writeup correlating Nmap scan activity across Wireshark, Suricata, and Splunk

How I work an alert

  1. Validate — is it real, what's the evidence
  2. Pivot — across host, user, and network indicators
  3. Timeline — reconstruct sequence, capture IOCs
  4. Contain / escalate — with justification, not guesswork
  5. Tune — turn the investigation into a detection or a fix, so it's faster next time

Skills

Splunk SPL · Windows Event Logs & Sysmon · Wireshark · Suricata · Nmap / Nessus · MITRE ATT&CK mapping

Currently building

Detection pack: encoded/obfuscated PowerShell, local admin creation + first-logon correlation, service-creation persistence, password-spray indicators, and anomalous outbound DNS.

Pinned Loading

  1. nicky-quistnicky-quistPublic

    About me

    1

  2. splunk-detectionssplunk-detectionsPublic

    SOC-style Splunk SPL detections with MITRE ATT&CK mapping, tuning notes, and validated evidence for each one.

    1

  3. windows-event-labswindows-event-labsPublic

    Hands-on Windows Security + Sysmon event log labs for SOC triage — process, network, and logon correlation.

    1

  4. rmf-security-assessment-samplermf-security-assessment-samplePublic

    A full NIST RMF security assessment lifecycle worked end-to-end for a fictional case-management system — categorization through ATO recommendation.

    1

  5. llm-cybersecurity-benchmarkllm-cybersecurity-benchmarkPublic

    Benchmarking LLM performance on cybersecurity SOC analysis tasks including detection engineering, threat reasoning, and incident response scenarios.

    HTML 1