Skip to content
View wahidhendrawan's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report wahidhendrawan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
wahidhendrawan/README.md
Cyber defense operations banner

Wahid Hendrawan

Blue Team Lead Β· Security Architect Β· DFIR Β· Threat Hunting Β· Threat Intelligence

I build practical security operations capabilities: detection engineering, incident response, threat hunting, intelligence workflows, DFIR tooling, and low-cost security architecture for teams that need security outcomes they can deploy, inspect, and maintain.

LinkedIn Portfolio Open Source


πŸ‘‹ Operator Snapshot

Area Current Focus
πŸ›‘οΈ Security Operations SOC engineering, alert triage, case workflow, response playbooks
🎯 Detection Engineering Sigma, SIEM/XDR content, MITRE ATT&CK mapping, multi-platform rules
πŸ•΅οΈ Threat Hunting IOC/IOA hypothesis building, telemetry pivoting, adversary behavior tracking
πŸ§ͺ DFIR Log analysis, forensic triage, incident reconstruction, investigation tooling
πŸ›°οΈ Threat Intelligence IOC enrichment, CVE prioritization, OSINT collection, operational reporting
πŸ—οΈ Security Architecture Low-cost security architecture, platform integration, defense capability roadmaps
βš™οΈ Automation Python, JavaScript, Docker, API integration, SOAR workflow automation
☁️ Cloud Security AWS/Azure/GCP hardening, Kubernetes, compliance automation, IaC security

πŸš€ Mission Board

πŸ”’ Automation-Hardening

Cross-platform security baseline auditing and controlled remediation for Linux, macOS, Windows, FreeBSD, Alpine, AWS, Azure, GCP, Kubernetes, Docker, and more. Audit β†’ Plan β†’ Apply β†’ Rollback.

Automation-Hardening Documentation

🧭 Detection-Rules

Cross-platform detection library β€” 836 rules, 9 platforms, 152 MITRE ATT&CK techniques. Sigma Β· Elastic Β· Splunk Β· Sentinel Β· Wazuh Β· Carbon Black Β· CrowdStrike Β· SentinelOne Β· Falco.

Detection-Rules Detection engineering

πŸ” YARA Sigma Studio

Convert YARA rules to Sigma detections and native SIEM/EDR queries with .yar import, IOC classification, MITRE ATT&CK tagging, CLI, API, and Docker.

YARA Sigma Studio YARA to Sigma

πŸ›°οΈ ThreatDock

Centralized threat intelligence and security operations platform for advisories, CVEs, IOCs, alert context, and case workflows.

ThreatDock Threat intelligence

πŸ”Ž Forensis

Threat analysis and digital forensics platform with log and network analyzers, memory triage, Sigma correlation, and MFA-enabled administration.

Forensis DFIR

🎯 GolekThreat

Threat hunting playbook engine for repeatable hunts, evidence tracking, ATT&CK coverage analysis, and analyst-ready reports.

GolekThreat Threat Hunting

πŸ“Š VulnBoard

Vulnerability management dashboard for tracking, prioritizing, and visualizing security findings across teams.

VulnBoard Vulnerability Management

πŸ—οΈ IaC WebApps

The Ultimate Multi-IaC Visual Platform. Design infrastructure visually and generate code for Terraform, OpenTofu, Pulumi, or Helm with real-time pricing.

IaC WebApps IaC


🧰 Arsenal

My hobby is learning new things. These are security, infrastructure, intelligence, automation, and observability tools I have used or recently studied.

πŸ›‘οΈ Network, Endpoint, and Security Platforms

AhnLab TrusGuard Fortinet FortiGate AlienVault Trend Micro Vision One VMware Carbon Black Cloudflare Mikrotik Cisco

🎯 SIEM, Detection, SOAR, and Case Management

Splunk ELK Stack Wazuh Sigma Shuffle TheHive Cortex DFIR IRIS IDSTower SELKS

πŸ›°οΈ Threat Intelligence, Adversary Emulation, and Forensics

SOCRadar Flashpoint Recorded Future OpenCTI OpenBAS MISP Vectr Velociraptor CyberChef

☁️ Cloud, DevOps, Automation, and Observability

GCP AWS Azure Docker Kubernetes Terraform Portainer Prometheus Grafana Ansible N8N


πŸ”“ Unlocking New Experience

  • System Engineer / Cyber Security Architect
  • Digital Forensics on Corporate
  • Trainer Cyber Security on BUMN
  • Automation Engineer
  • Head of Cyber Security Team

πŸ“Œ Current Direction

  • Learning new security and infrastructure tooling continuously.
  • Designing low-cost IT security architecture that is practical to operate.
  • Publishing reusable detection engineering and threat hunting content.
  • Improving practical SOC, DFIR, and CTI tooling for small and medium security teams.
  • Sharing knowledge for the advancement of Indonesian cybersecurity education.

🐍 Contribution Game

GitHub contribution snake

🀝 Connect

Pinned Loading

  1. yara-sigma-webui yara-sigma-webui Public

    YARA Sigma Studio: convert YARA rules to Sigma detections and native SIEM/EDR queries with .yar import, IOC classification, MITRE ATT&CK tagging, mapping pipelines, CLI, API, and Docker Compose.

    Python 1

  2. Detection-Rules Detection-Rules Public

    Cross-platform detection rules library β€” 836 rules, 9 platforms, 152 MITRE ATT&CK techniques, ZERO single-platform gaps. Sigma Β· Elastic Β· Splunk Β· Sentinel Β· Wazuh Β· Carbon Black Β· CrowdStrike Β· S…

    Python 1

  3. Forensis Forensis Public

    Threat analysis and digital forensics platform with log and network analyzers, memory triage, playbook helper, Sigma correlation, and MFA-enabled administration.

    Python

  4. ThreatDock ThreatDock Public

    A centralized platform for threat intelligence and security operation management.

    JavaScript 2

  5. PagerWesi PagerWesi Public

    Security baseline auditing & controlled remediation for Linux, macOS, Windows, Cloud, Kubernetes, Docker, and Terraform.

    Python

  6. GolekThreat GolekThreat Public

    Threat hunting playbook engine for repeatable hunts, evidence tracking, ATT&CK coverage, and analyst-ready reports.

    Python