Skip to content
View PrototypePrime's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report PrototypePrime

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
PrototypePrime/README.md

Mathan Subbiah

🔐 Senior Security Engineer | Detection Specialist | Security Tooling

Engineering proactive, scalable security systems that drastically reduce adversary dwell time.

LinkedIn Email

Splunk Microsoft Defender Cortex XDR Python MITRE ATT&CK


🛡️ Engineering Philosophy

"The best threat hunting is done before the threat knows it's being hunted."

I believe in Proactive Defense and High-Fidelity Detection. My approach focuses on Adversary Emulation and Defense Optimization — rigorously testing security controls against realistic attack scenarios, minimizing false positives, and ensuring SOC teams focus on true signals, not noise.


🔭 Current Focus

Area Description
🧪 Attack Simulation Enhancing Event-Horizon with multi-vector attack telemetry for realistic detection validation
📊 SIEM Engineering Expanding production-ready detection coverage in Splunk SPL and Microsoft KQL
📱 Splunk App Development Building a custom SOC operations app targeting Splunkbase deployment
🛠️ Security Tooling Engineering automation tools (SCOUT, Hyper-SOC) to eliminate analyst toil

🚀 Core Expertise

Domain Technologies Value
Detection Engineering Splunk SPL, KQL, XQL Production-grade, MITRE-aligned detection rules across SIEM & EDR
Splunk Dashboards & Reports SPL, Splunk UI, Data Models Design and deliver executive-ready dashboards, analyst reports, and real-time SOC monitoring views
Security Tooling Python, Shell Build tools that accelerate testing, training, and SOC workflows
Threat Intelligence CVE tracking, IOC management, OSINT Operationalize threat data into actionable defence
Threat Hunting Behavioral analysis, custom queries Surface stealthy threats that evade automated controls
SOC Operations & Incident Response SIEM, EDR, Ticketing Rapid alert triage, containment, and incident lifecycle management

✨ Project Showcase

🔬 Security Tooling & Platforms

Project Stack Description
🌐 SCOUT Python Security & CVE Outbreak Universal Tracker — Real-time CVE monitoring, outbreak detection, and prioritization engine for enterprise SOC teams. Tracks zero-days and active exploitation across global threat feeds.
🔭 Event-Horizon Python / AI Production-quality security log generator supporting 80+ platforms (Firewalls, Cloud, Endpoints, EDR). Generates realistic, timestamped attack telemetry for detection validation, SOC training, and dashboard testing. Features AI-powered attack simulation and "Golden Master" templates.
🖥️ Hyper-SOC Shell One-command SOC Analyst workstation builder for Windows & Linux. Automates the full setup of a comprehensive SOC analyst environment — tools, integrations, and configurations — from a single script.
🕵️ ProInfo Intelligence Suite TypeScript / React Professional-grade OSINT dashboard for streamlined IP reconnaissance and threat assessment. Features a "Cyber-Heatmap" for threat density, force-directed graph topology, and high-fidelity CSV/PDF reporting.
🤖 Custom AI-Powered GPT LLMs / Prompt Engineering A specialized, knowledge-based GPT designed to democratize complex security expertise — streamlining analyst workflows, policy adherence checks, and detection logic creation.

📡 Detection Libraries (Actively & Continuously Updated)

🔄 These libraries are living repositories — new rules, techniques, and coverage are added regularly as threats evolve.

Project Query Language Description
Splunk SPL Detection SPL 50+ production-ready detection rules, reports & dashboards mapped to MITRE ATT&CK. Includes a Techniques Library for SPL optimization and Universal Detection Archetypes. Deployable rule set and engineering cookbook.
🛡️ Microsoft Defender KQL KQL Advanced hunting queries for M365 & Azure environments. Covers identity attacks (impossible travel, OAuth abuse), endpoint threats, and cloud telemetry — optimized for cloud-scale detection.
🔎 Cortex XDR XQL Detection XQL Specialized XQL detection library optimized for Cortex XDR's BIOC framework. Focuses on behavioral detection to thwart fileless attacks and living-off-the-land (LotL) tactics.

🚧 Coming Soon

Project Stack Description
📊 Splunk SOC App (In Development) Splunk / SPL / Python A full-featured SOC Operations App targeting Splunkbase deployment. Consolidates threat detection, alert triage, CVE tracking, and analyst workflows into a single unified Splunk application.

📈 Security Coverage at a Glance

Detection Libraries:  Splunk SPL · Microsoft KQL · Cortex XDR XQL
MITRE Coverage:       Initial Access · Execution · Persistence · Privilege Escalation
                      Defense Evasion · Credential Access · Discovery · Lateral Movement
                      Collection · Exfiltration · Command & Control · Impact
Platforms Supported:  Windows · Linux · macOS · Azure · M365 · Palo Alto · Fortinet · +more

Popular repositories Loading

  1. Splunk_SPL_Detection Splunk_SPL_Detection Public

    In this Repo I will be sharing all the rules/reports/Dashboard/APP created

  2. PrototypePrime PrototypePrime Public

  3. Microsoft_Defender_KQL_Detection Microsoft_Defender_KQL_Detection Public

  4. Cortex_XDR_XQL_Detection Cortex_XDR_XQL_Detection Public

    XQuery

  5. Custom_AI-Powered_GPT Custom_AI-Powered_GPT Public

  6. ProInfo ProInfo Public

    TypeScript