Skip to content
View karemfaisal's full-sized avatar
Block or Report

Block or report karemfaisal

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
karemfaisal/README.md

Welcome! 👋

I am Karem Ali, an experienced Purple Team consultant with over 4 years of experience in DFIR, Offensive Operations, and Product(s) assessments.

I love the hidden competition between the defenders and the threat actors, what make me always want to learn about their techniques and how we enhance our detection capabilities.

As Sun Tzu said once

If you know the enemy and know yourself, you need not fear the result of a hundred battles.

My profile shall contains a mix between defensive security and offensive security, and I hope you find here a valuable shared work.

Have a nice day!

My GitHub Stats

Karem Ali's github stats Top Langs

Reach me @

Karem Ali | email Karem Ali | email Karem Ali | Blog

Pinned Loading

  1. SMUC SMUC Public

    Simplified MITRE Use Cases, it describes the Attack and Detection

    Common Lisp 37 16

  2. Emulate-And-Detect Emulate-And-Detect Public

    This repositroy will contains attack emulation tests along with the detection rules for it

    C 4

  3. CB-Boost CB-Boost Public

    This repo contains scripts that utilizes Carbon Black EDR for boosting its IR and detection cababilities

    Python 8 1

  4. KillRat KillRat Public

    Script to Kill Rat

    PowerShell 6 3

  5. Hybrid-Analysis-API Hybrid-Analysis-API Public

    Powershell script to retrieve valuable data from Hybrid Analysis

    PowerShell 2 1

  6. Scan-IP Scan-IP Public

    This PowerShell script aims to automate the process of scanning IPs in SOC (Security Operation Center)

    PowerShell 1 1