Skip to content
View jacobdcook's full-sized avatar

Block or report jacobdcook

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jacobdcook/README.md

Jacob Cook

Detection & Security Automation Engineer

   

I build reliable triage from noisy telemetry — behavioral Sigma detections, SIEM tuning, identity attack detection, and SOAR automation — each documented with real false-positive scenarios and repeatable response playbooks.

Currently a Service Desk Analyst moving toward a blue-team / detection role, and pursuing an MS in Cybersecurity at Western Governors University (expected October 2026).

Tech & tooling

Languages & frameworks

Python TypeScript JavaScript React Next.js Node.js C

Security, cloud & infrastructure

Sigma MITRE ATT&CK Wazuh Okta Terraform Azure AWS Docker Linux

Detection engineering & blue team

Featured — Stryker / Intune Detection Pack — Detection-as-code for Intune MDM abuse, modeled on the 2026 Stryker/Handala attack: Sigma rules, KV-store enrichment, and response playbooks mapped to MITRE ATT&CK.

Blue Team SOC Monitoring Lab

SOAR-lite — IR Orchestrator

Network Behavior Analyzer


Wazuh SIEM stack (Docker) with Linux log ingestion, brute-force detection, and documented alert triage + rule IDs
Project Link


Lightweight SOAR that ingests SIEM alerts and runs automated response playbooks for common threats
Project Link


Detects C2 beaconing and data exfiltration through network behavioral analysis (LLM-assisted summaries)
Project Link

More detection work:

Cloud & infrastructure security

Cloud Infrastructure Security Auditor

Azure Cloud Hardening Lab


Static analysis + live Azure auditing for Terraform and cloud misconfigurations, with a remediation-oriented workflow
Project Link


Hardened, secure Azure infrastructure deployed with Terraform
Project Link

AI & security tooling

Where I lean on LLMs as a force-multiplier for security and productivity work:

G3-GPT — Document Retrieval

AI Log Auditor

Synapse AI Chat


RAG platform with Azure SSO and role-based access control for enterprise document retrieval
Project Link


Log-analysis pipeline with automated PDF reporting and LLM-assisted triage summaries
Project Link





Multi-model desktop chat client for local Ollama models
Project Link

Also: Whisper Transcribe (local faster-whisper + CUDA transcription) · Claude Code Skills (reusable Claude Code skill packs).

Education & certifications

  • Master's in Cybersecurity — Western Governors University (Expected October 2026)
  • B.S. in Computer Science — California State University, Sacramento
  • CompTIA SecurityX (CAS-005) — 2026
  • CompTIA PenTest+ (PT0-003) — 2026
  • CompTIA CySA+ (CS0-003) — Feb 2026
  • CompTIA Security+ (SY0-701) — Jan 2026
  • CompTIA CSIE (Secure Infrastructure Expert) — stackable credential

GitHub stats

Jacob's GitHub stats

Pinned Loading

  1. stryker-intune-detection-pack stryker-intune-detection-pack Public

    Detection-as-code pack for Microsoft Intune MDM abuse (inspired by the March 2026 Stryker/Handala attack). Sigma rules, KV store enrichment, and response playbooks mapped to MITRE ATT&CK.

    Python 1

  2. okta-detection-engine okta-detection-engine Public

    Okta Detection Engine Lab - Python-based detection for MFA Fatigue, Impossible Travel, and more.

    Python 1

  3. soar-incident-orchestrator soar-incident-orchestrator Public

    A lightweight Security Orchestration, Automation, and Response (SOAR) platform that ingests alerts and executes automated playbooks.

    Python

  4. cloud-security-auditor cloud-security-auditor Public

    Security auditor for Terraform and live Azure environments — static analysis, misconfiguration checks, and a remediation workflow.

    Python

  5. network-behavior-analyzer network-behavior-analyzer Public

    Network monitoring tool focused on behavioral analysis to identify anomalies like data exfiltration or beaconing.

    Python

  6. blue-team-soc-monitoring-lab blue-team-soc-monitoring-lab Public

    Wazuh SIEM stack (Docker) with Linux log ingestion, brute-force detection, and documented alert triage + rule IDs.

    Python