الملفات
ghaymah-exam-MazenHassan-Se…/README.md
2026-07-28 01:14:23 +00:00

1.9 KiB

☁️ Ghaymah Internship Exam - SecOps Track

Candidate Name: Mazen
Track: SecOps (Security Operations)

🎯 Project Overview

This repository contains the practical implementations, infrastructure scripts, and postmortem reports for the Ghaymah Internship Exam (SecOps Track). It demonstrates a cloud-native approach to security, focusing on automated auditing, incident response, SIEM log correlation, and disaster recovery.

📂 Repository Structure

ghaymah-exam-Mazen-SecOps/
├── q1-deploy-monitor/
│   ├── security-audit.md       # 15-point Cloud Security Audit Checklist
│   └── health-check.sh         # Automated bash script for ports, SSL, and permissions
├── q2-postmortem/
│   └── postmortem-report.md    # Incident Response Plan & Timeline for API Brute Force
├── q3-privacy-assessment/
│   ├── privacy-assessment.md   # DevTools inspection report for mithal.space
│   └── assets/                 # Evidence screenshots for the assessment
├── q4-siem/
│   ├── analyzer.py             # Python-based Log Correlation Analyzer
│   ├── dashboard.html          # SIEM Alerts UI
│   └── deployment-plan.md      # Block Storage and NGINX deployment strategy
├── q5-ransomware/
│   └── ransomware-response.md  # RTO/RPO strategies and 3-2-1 backup architecture
├── common-mortakaz/
│   ├── integration.md          # Integration proposals
├── common-qabilah/
│   └── qabilah-profile.txt     # Qabilah profile link text file
└── README.md

🔗 Mandatory Requirements (Task B) Qabilah Network Profile: https://qabilah.com/profile/mazenelsayad99/professional-profile

🚀 Execution Instructions To test the Python SIEM (Q4) locally without browser CORS restrictions:

Bash
cd q4-siem
python3 analyzer.py
python3 -m http.server 8000
# Then open http://localhost:8000/dashboard.html in your web browser