about skills experience projects write-ups certs contact
DFIR

> SOC Analyst  ·  DFIR Specialist  ·  Malware Analyst

NIRARAZI

SOC Analyst at El Al Israel Airlines.
Investigating threats. Finding what others miss.
20+ tools. 119 rooms. Top 2%.

View Projects Get In Touch
3+Years in Cyber
Top 2%TryHackMe
20+Tools Built
119Rooms Completed
01

About

SOC Analyst at El Al Israel Airlines, hunting threats across one of the most targeted industries in the world. My focus is DFIR, malware analysis, and threat intelligence — not as checkboxes, but as a way of thinking.

Three years of self-driven study converted into real investigations, real incidents, and 20+ tools built from scratch — because when the right tool doesn't exist, you build it. From automated IOC enrichment pipelines to full PCAP analysis frameworks, every tool came from a real gap in a real workflow.

A few years ago I was standing on a candy factory floor. No degree. No connections. No roadmap. Just an obsession with understanding how things work and an unwillingness to stay where I was. I taught myself everything — every tool, every technique, every late night lab — until the factory was a memory and the SOC was the reality.

From the production line to protecting an airline. That's not a career path. That's a mindset.

✈️
Current Role
SOC Analyst — El Al Israel Airlines
📍
Location
Petah Tikva, Israel
🎯
Focus Areas
DFIR · Malware Analysis · Threat Intel
⚔️
TryHackMe
Top 2% · Rank 28,428 · 33 Badges
🛠️
Tools Built
20+ custom security tools
02

Experience

SOC Analyst
El Al Israel Airlines · Ben Gurion Airport · via YouCC
Threat detection and incident response for one of the world's most targeted aviation organizations. Working across EDR, SIEM, and identity platforms in a high-pressure, high-stakes environment. Focus on DFIR, alert triage, and adversary tracking.
DFIRThreat HuntingSentinelOneActive DirectorySilverfort
JUN 2025 — MAY 2026
SOC Analyst & Mentor
TripleCyber · Tel Aviv
Handled real-world alert triage, malware investigations, and incident response across multiple client environments. Mentored 5 junior analysts using a Socratic teaching approach — breaking down complex attack chains until the analyst could reason through them independently.
SplunkCynetMS DefenderTrend MicroMentoring
03

Skills & Tools

SplunkSIEM
SentinelOneEDR
MS DefenderEDR
CynetEDR
WiresharkNetwork
TsharkNetwork
VolatilityMemory
FTK ImagerDFIR
Registry ExplorerDFIR
RegipyDFIR
IDA ProReversing
YARADetection
PythonScripting
BashScripting
PowerShellScripting
MISPThreat Intel
n8nAutomation
Active DirectoryIdentity
Snort 3IDS/IPS
Kali LinuxOS
04

Projects

// 002 Threat Intelligence · n8n
IOC Hunter

Automated IOC enrichment pipeline with Telegram bot interface. Integrates VirusTotal, OTX, MalwareBazaar, AbuseIPDB and more. IDN homograph detection + typosquat scoring against 40+ brands. 4-tier verdict system.

n8nPythonVirusTotalTelegramOTX
View on GitHub →
// 003 Network Forensics · Python
Pcap Whisperer

Python tool wrapping Snort 3 with automatic rule downloading and color-coded verdicts. Automates the full pipeline: download rules → install Snort → run → parse → verdict. Clean CLI, no noise.

PythonSnort 3PCAP
View on GitHub →
// 004 DFIR · PowerShell
Hash-Based IOC Scanner

Fast hash-based IOC sweep for DFIR investigations. Scans a target system against a predefined hash database and returns confirmed matches with full file paths. Built for speed in live incident response.

PowerShellDFIRIOC
View on GitHub →
// 005 DFIR · Batch
WinCurler

Windows forensic collection script for rapid incident response triage. Collects host info, running processes, persistence mechanisms (Run keys, Startup, SafeBoot), PowerShell history, and scheduled tasks into categorized folders.

BatchWindows ForensicsIR Triage
View on GitHub →
// 006 Malware Analysis · Report
WannaCry Analysis

Published deep-dive malware analysis report on WannaCry ransomware. Covers static and dynamic analysis, kill switch mechanism reverse engineering, encryption analysis, and full IOC extraction.

IDA ProYARAVolatilityWireshark
Read on LinkedIn →
// 007 DFIR · Windows Forensics
DFIR Home Lab

Fully structured Windows DFIR investigation environment organized into 9 forensic categories: Acquisition & Mounting, Memory Analysis, Network Forensics, Persistence Analysis, Artifact Analysis, Threat Hunting, Forensic Suites, Specialized Tools, and more. 15+ specialized tools deployed and ready for live investigations.

FTK ImagerAutopsyRegistry ExplorerRegRipperAmcacheParserPECmdMailViewLinkParser
05

Write-Ups

Malware Analysis · Published
WannaCry Deep Dive

Full static and dynamic analysis of the WannaCry ransomware. Reverse engineered the kill switch mechanism using IDA Pro, traced the EternalBlue exploitation chain, extracted encryption keys, and built a custom YARA rule set. Published on LinkedIn.

IDA ProYARAVolatilityWiresharkEternalBlue
Read on LinkedIn →
Tool Build · Network Forensics
Building Pcap Crawler

17-module interactive PCAP analysis framework built for real SOC workflows. Each module came from a real gap: credential extraction, ARP duplicate detection, OS fingerprinting, GeoIP on suspicious IPs, VirusTotal upload, malware carving. Point it at a capture file, get forensic intel back in seconds — no manual tshark gymnastics.

BashTsharkGeoIPVirusTotal APIForemost
View on GitHub →
Tool Build · Threat Intelligence
Building IOC Hunter

Automated IOC enrichment pipeline with a Telegram bot as the interface. Submit an IP, URL, domain, or hash — it queries VirusTotal, OTX, MalwareBazaar, Pulsedive, URLScan, and ThreatFox simultaneously and returns a structured 4-tier verdict. Includes IDN homograph detection and Levenshtein-based typosquat scoring against 40+ brands. Hosted on n8n Starter for always-on cloud execution.

n8nPythonVirusTotalTelegramOTXLevenshtein
View on GitHub →
Tool Build · Network Forensics
Building Pcap Whisperer

The gap: Snort 3 is powerful but takes 15 minutes to set up for every PCAP you want to scan. So I automated the entire pipeline — rule download, Snort install, execution, result parsing, and color-coded verdict output. One command, zero friction.

PythonSnort 3PCAPAutomation
View on GitHub →
06

Certifications

🔍
CRDFA
Certified RTL Digital Forensic Analyst
Red Team Leaders · Score: 91%
💼
IBM Cybersecurity Analyst
Professional Certificate · Coursera / IBM
Jan 2026 · 14 Courses
🏛️
National Cyber Directorate
Israeli National Cyber Directorate
Official Government Program
🎓
Certificate of Excellence
John Bryce
Cybersecurity Studies
🪟
Windows Forensics
Windows Forensics International Certificate
Digital Forensics
⚔️
TryHackMe Master Badge
Top 2% Global · Rank 28,428
119 Rooms · 33 Badges
07

Contact

Open to connecting with security professionals, researchers, and anyone interested in collaboration. Whether it's tools, investigations, or just talking cyber — reach out.

Send me an email →