Skip to content
View BigXthaBug's full-sized avatar
πŸ›
πŸ›

Block or report BigXthaBug

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
BigXthaBug/readme.md

BigXthaBug πŸ›πŸ”’πŸ’₯

Security Researcher | Detection Engineer | Threat Hunter | Adversary Emulator

BigXthaBug logo

Breaking things to build better defenses.
Chasing APTs, crafting rules, emulating red-team TTPs, and turning bugs into detections.

Focus Areas

  • πŸ” Threat Hunting – Proactive, hypothesis-driven hunts across endpoints, cloud & networks
  • πŸ› οΈ Detection Engineering – Building scalable, low-FP detections (Sigma, YARA, Elastic, Splunk, custom queries, etc.)
  • βš”οΈ Threat Emulation – Adversary emulation, purple teaming, ATT&CK-based red-team ops
  • πŸ§ͺ Security Research – Reverse engineering malware, vuln discovery, exploit dev & analysis

Tech Stack / Tools

  • Languages: Python β€’ Go β€’ PowerShell
  • Detection: Sigma β€’ YARA β€’ Zeek β€’ Suricata β€’ Elastic β€’ Splunk β€’ Microsoft Sentinel
  • Hunting/EDR: Velociraptor β€’ GRR β€’ Osquery β€’ Falcon β€’ Defender XDR β€’ CrowdStrike
  • Emulation: Caldera β€’ Atomic Red Team β€’ Infection Monkey β€’ Metta
  • Reverse: Ghidra β€’ IDA Pro β€’ radare2 β€’ x64dbg

Currently vibing on

  • Living-off-the-land binaries & techniques (LOLBAS)
  • Cloud threat emulation (Azure AD / AWS IAM abuse paths)
  • Next-gen ransomware TTPs & detection gaps
  • AI-assisted threat hunting & anomaly baselining

Popular repositories Loading

  1. BigXthaBug BigXthaBug Public

    Me

  2. detection-rules detection-rules Public

    Forked from elastic/detection-rules

    Python

  3. atomic-red-team atomic-red-team Public

    Forked from redcanaryco/atomic-red-team

    Small and highly portable detection tests based on MITRE's ATT&CK.

    C

  4. sigma sigma Public

    Forked from SigmaHQ/sigma

    Main Sigma Rule Repository

    Python

  5. Azure-Sentinel Azure-Sentinel Public

    Forked from Azure/Azure-Sentinel

    Cloud-native SIEM for intelligent security analytics for your entire enterprise.

    Python

  6. security_content security_content Public

    Forked from splunk/security_content

    Splunk Security Content

    Python