Skip to content
View kekoag6's full-sized avatar

Highlights

  • Pro

Block or report kekoag6

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kekoag6/README.md

Kekoa Giron 🔐

Typing banner: Threat Hunting, Incident Response, Detection Engineering, Digital Forensics, KQL, Vulnerability Management

LinkedIn Instagram Based in Honolulu, HI


👋 About Me

I'm a cybersecurity practitioner who learns by doing. These projects cover the full defensive cycle: finding and fixing vulnerabilities, hunting for attackers in real telemetry, and turning what I find into detections. Each repository includes the queries, scripts, and evidence behind the work.

Across all of it I try to hold one standard: separate what the telemetry proves from what it can't show, and say which is which. "No evidence of exfiltration" and "no visibility into exfiltration" are different findings, and only one of them lets you close an incident.

  • 🎓 Education: M.S. Cybersecurity and Information Assurance (WGU) · BBA in Management, University of Hawaiʻi at Mānoa (Shidler College of Business)
  • 🛡️ Certifications: CompTIA CySA+, PenTest+, Security+ · ISC2 CC · Google Cybersecurity
  • 🔎 Focus areas: threat hunting, incident response, detection engineering, digital forensics, vulnerability management
  • 🛠️ Side project: building Rosterborn, a fantasy football app, with heavy AI assistance and mild stubbornness
  • 🏃 Outside of work: running, volleyball, and taking fantasy football more seriously than is defensible. Vibe coding is the hobby now — mostly a retired gamer these days.

🚨 Threat Hunting and Incident Response

Project What it shows
TideGlass: AI Agent Intrusion Investigation Traced an AI-agent attack across 8 log sources in Microsoft Sentinel, from exploit to AWS credential theft, lateral movement, and exfiltration of 2.8M customer records — 36 minutes from exploit to exfiltration, inside a 52-minute agent session. 28 findings with the 58 KQL queries behind them, MITRE ATT&CK and ATLAS mapping, 8 behavior-based detections, and an explicit account of what the telemetry could not establish.
Meridian: Healthcare Host Compromise Full intrusion chain on a Linux healthcare web host — 18,454-request content discovery, file disclosure to credential reuse in 57 seconds, SUID root escalation (auid=1001, euid=0), and a confirmed patient-data export. Two findings beyond the chain: the incident was never contained, and the largest evidence gap was self-inflicted — the estate's own sweep removed Sysmon 39 minutes before the attacker arrived.
MySQL Ransomware — Honeynet Investigation Real intrusion activity against a honeynet I built and instrumented. 12 external sources brute-forced an exposed MySQL service, enumerated every schema, issued 35 DROP statements, and left a Bitcoin ransom demand. Full timeline, IOC extraction with negative validation, and an explicit account of what the logs could not establish.
Cryptojacking via Spoofed Vendor Update Three helpdesk tickets about a slow application traced to an XMRig miner on a file server, installed through a spoofed vendor email after Defender was disabled by Group Policy. Wazuh correlation, containment, and the detection gaps that cost five hours.

🔬 Digital Forensics

Project What it shows
Endpoint Forensic Triage — Defender Live Response Triage of a Windows 11 endpoint that surfaced an active Tor circuit — four established relay connections and a local SOCKS proxy, from a portable browser that left no uninstall entry. Four artifact classes corroborate it; decoded registry FILETIMEs reconstruct the download → extract → execute → connect chain to the second.

📡 Detection Engineering

Project What it shows
Sentinel SOC Visibility Workbooks Four deployable Microsoft Sentinel workbooks turning Defender and flow telemetry into geographic triage views: inbound authentication origins, outbound C2 fan-in, exfiltration by byte volume, and allowed inbound traffic matched against threat intelligence. Commented KQL, deduplicated TI joins, companion grids for every map.

⚠️ Vulnerability Management and Hardening

Project What it shows
Risk-Based Vulnerability Management Program A full scan → prioritize → remediate → verify cycle. Six remediation rounds took a Windows host from 2 Critical / 8 High / 12 Medium / 1 Low to 0 / 0 / 2 / 1 — 23 actionable findings down to 3, an 87% reduction — with the three remaining risks formally accepted and documented rather than suppressed. Ships the remediations as idempotent PowerShell, each script carrying the Tenable plugin ID it clears so the automation reconciles against the scan evidence. Includes API-driven Linux scanning.
Windows 11 DISA STIG Remediation Ten idempotent, self-validating PowerShell scripts remediating Windows 11 STIG controls — three CAT I, plus Azure Trusted Launch with Secure Boot and vTPM. Each documents both the registry and Group Policy path and reads the value back to confirm it landed. Ships with a read-only compliance checker covering all ten.

📋 Governance, Risk, and Compliance

Project What it shows
Security Control Gap Assessments Three assessments across healthcare, retail, and federal-contractor cloud migration. NIST SP 800-53 control ratings with the reasoning behind why two controls in the same family rate differently, PCI DSS and GDPR mapped to shared controls, and cloud security planning under an active audit deadline.

🧰 Toolkit

Microsoft Sentinel Microsoft Defender for Endpoint KQL Azure AWS Tenable Wazuh PowerShell Bash Linux MySQL MITRE ATT&CK MITRE ATLAS DISA STIGs NIST SP 800-53


🏅 Certifications
Certification Issuer Year
CySA+ CompTIA 2026
PenTest+ CompTIA 2026
Certified in Cybersecurity (CC) ISC2 2026
Security+ CompTIA 2025
Google Cybersecurity Certificate Google 2025
Google Project Management Certificate Google 2024
🗂️ Other repositories
Repository Contents
cyber-projects Original submission reference for the STIG remediation scripts. Documented in full at Windows-11-STIG-Remediation.

📫 Always happy to talk shop about detection engineering and incident response.
Connect on LinkedIn

Pinned Loading

  1. Threat-Hunting-Scenario-TideGlass Threat-Hunting-Scenario-TideGlass Public

    Incident investigation of an AI-agent intrusion across AWS, Linux, and PostgreSQL using Microsoft Sentinel and KQL

  2. Honeynet-MySQL-Ransomware-Incident Honeynet-MySQL-Ransomware-Incident Public

    SOC incident investigation of real intrusion activity against a MySQL honeynet: brute-forced root access, 35 destructive DROP statements, and a Bitcoin ransom demand. KQL, IOC extraction, and expli…

  3. Endpoint-Forensic-Triage-MDE Endpoint-Forensic-Triage-MDE Public

    Forensic triage of a Windows 11 endpoint from a Defender for Endpoint Live Response package. Found an active Tor circuit; reconstructed the full execution chain from netstat, process tree, prefetch…

  4. Sentinel-SOC-Visibility-Workbooks Sentinel-SOC-Visibility-Workbooks Public

    Four Microsoft Sentinel workbooks turning Defender and flow telemetry into geographic SOC triage views: inbound auth origins, outbound C2 fan-in, exfiltration by volume, and threat-intel-matched al…

  5. Vulnerability-Management-Program Vulnerability-Management-Program Public

    Risk-based vulnerability management program. Six verified remediation cycles took a Windows host from 2 Critical / 8 High / 12 Medium to 0/0/2 with documented risk acceptance. Tenable, Azure, CVSS,…

    PowerShell

  6. Windows-11-STIG-Remediation Windows-11-STIG-Remediation Public

    Ten idempotent, self-validating PowerShell scripts remediating Windows 11 DISA STIG controls (3x CAT I), plus a read-only compliance checker covering all ten.

    PowerShell