Skip to content
View MaryamShazz's full-sized avatar

Block or report MaryamShazz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MaryamShazz/README.md
Maryam Shahzad

Hi, I'm Maryam 👋

I'm a Computer Science undergraduate interested in cybersecurity, AI driven threat detection, digital forensics, and cloud security. Lets just say anything related to Computer Science and Security.

I build security projects to explore detection, investigation, automation, and reproducible security research, with a particular interest in APT detection and defensive security.

🎯 What I'm working on

  • 🔎 AI driven threat detection —> anomaly detection and security monitoring
  • 🕵️ Digital forensics & APT investigation —> evidence analysis, timelines, and IOC investigation
  • ☁️ Cloud security —> security controls, governance, and policy simulation
  • 🔬 Reproducible security research —> evaluation methods for provenance based APT detection
  • 🛡️ Open-source security —> contributing detection improvements to Wazuh

🔬 Research

Making APT Detection Research Reproducible

Preprint / Technical Report [submitted for peer review] —> 2026

A proposed evaluation protocol and unified scoring framework for provenance based security tools, focusing on reproducibility and comparable evaluation of APT detection approaches.

Topics: APT Detection · Provenance · Reproducibility · Security Evaluation

📄 View the preprint on Zenodo

🛡️ Selected Work

☁️ Cloud Policy Cost & Security Simulator

A web based digital twin for exploring cloud governance, security policies, cost estimation, threat detection, and remediation.

Focus: Cloud Security · FinOps · Security Governance · AI

View Repository

🧠 SOC Simulation Platform

An AI assisted SOC environment with threat scoring, MITRE ATT&CK mapping, real time events, and a reproducible 9-scenario benchmark suite.

Focus: SOC · Threat Detection · MITRE ATT&CK · Security Automation

View Repository

🌐 AI Network Anomaly Detector

A network intrusion detection project using Isolation Forest to identify anomalous traffic and present risk based investigation results.

Focus: Machine Learning · NIDS · Anomaly Detection · Python

View Repository

☁️ Huawei Cloud Security Hardening Defense Lab

A practical cloud security lab covering IAM, VPC, security groups, firewall controls, logging, monitoring, and backup.

Focus: Cloud Security · IAM · Defensive Security

View Repository

🕵️ Digital Forensics & APT Incident Investigation Lab

A simulated APT investigation combining Autopsy, Volatility 3, Windows event logs, IOC analysis, evidence correlation, and MITRE ATT&CK mapping.

Focus: Digital Forensics · Incident Response · APT Investigation

View Repository

📡 APT Network Traffic Investigation & Detection Lab

A network focused investigation environment for examining suspicious traffic and APT related activity through network analysis and detection tooling.

Focus: Network Forensics · Wireshark · Zeek · Suricata

View Repository

🌱 Open Source

Wazuh

Contributed an upstream detection rule for repeated local PAM authentication failures, addressing repeated authentication attempts where a source IP may not be available.

Pull Request: Wazuh PR #38270

🛠️ Technical Areas

Security:
Wazuh · MITRE ATT&CK · Digital Forensics · Incident Response · Network Security · Cloud Security

Security Tools:
Autopsy · Volatility 3 · Wireshark · Zeek · Suricata

Programming & Development:
Python · Flask · React · JavaScript · SQL · Git

Data & AI:
Pandas · Scikit-learn · Isolation Forest · Anomaly Detection

📚 Training

  • Google Cybersecurity Professional Certificate -> completed all 9 courses
  • Huawei HCIA-Security V4.0 —> course completion
  • TryHackMe SOC Level 2 —> practical SOC training

📖 Currently Learning

  • Security Operations & Detection Engineering
  • Advanced Network Traffic Analysis
  • Digital Forensics & Incident Response
  • AI applications in cybersecurity

🤝 Connect

Email | LinkedIn | GitHub


Just a curious learner. :)

Pinned Loading

  1. Cloud-Policy-Cost-and-Security-Simulator Cloud-Policy-Cost-and-Security-Simulator Public

    Digital twin for exploring cloud security policies, cost, threat detection, and remediation.

    Python

  2. soc-simulation-platform soc-simulation-platform Public

    AI assisted SOC simulation platform with threat scoring, MITRE ATT&CK mapping, and reproducible scenarios.

    JavaScript

  3. AI-Network-Anomaly-Detector AI-Network-Anomaly-Detector Public

    Machine learning network anomaly detector using Isolation Forest and risk based investigation.

    Python

  4. Huawei-Cloud-Security-Hardening-Defense-Lab Huawei-Cloud-Security-Hardening-Defense-Lab Public

    Practical cloud security lab covering IAM, network controls, monitoring, logging, and backup.

    HTML

  5. Digital-Forensics-and-APT-Incident-Investigation-Lab Digital-Forensics-and-APT-Incident-Investigation-Lab Public

    A reproducible host based digital forensics and APT investigation lab using synthetic Windows evidence, explainable triage, MITRE ATT&CK mapping, evidence provenance and an interactive Streamlit in…

    Python

  6. APT-Network-Traffic-Investigation-and-Detection-Lab APT-Network-Traffic-Investigation-and-Detection-Lab Public

    Network forensics lab for investigating suspicious traffic using Wireshark, Zeek, and Suricata.

    Python