Skip to content
View AbdallaElzedy's full-sized avatar

Block or report AbdallaElzedy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AbdallaElzedy/README.md

Abdalla Elzedy, information security engineer, quantitative developer and founder

Information security engineer, nine years across financial services, higher education, and enterprise technology. The work spans detection engineering and threat hunting, incident response and investigation, penetration testing and vulnerability management, and identity and data governance in hybrid Azure and on-premises environments. I build the tooling that supports it, mostly in Python and PowerShell.

Identity Intelligence Engine

Enterprise platform, 2024 to present. A hybrid identity data catalog that correlates Azure Entra ID, on-premises Active Directory, LDAP, and SQL records into a single model with source-of-record lineage, under a unified metadata schema and account classification taxonomy. Automated data quality logic surfaces duplicates, orphaned records, and stale identities. Microsoft Graph access runs through dedicated app registrations with least-privilege permissions and managed identities, so the pipeline stores no secrets. Python and Flask backend with connection pooling and concurrent multi-source ingestion, shipped through GitHub Actions with Trivy scanning.

Neural Predictiva

Neural Predictiva

Founder. A quantitative FX research system running a live multi-pair fleet on hourly data. Genetic algorithm strategy search with walk-forward out-of-sample evaluation, a broker execution simulator that models spread, slippage, swap, margin, and position limits, and a daily automated reoptimization pipeline. Backtest kernels are numba-compiled, and live monitoring runs through a PHP and MySQL dashboard. Strategy selection is governed by pre-registered experiments and deflated performance statistics.

Repositories

  • Cortex-XSIAM XQL detection packs and threat hunting queries for Palo Alto Cortex XSIAM: account takeover chains, Microsoft 365 and Entra ID monitoring, NGFW traffic analysis, Windows event log investigation, and endpoint activity, plus XQL function and XDR data model references.
  • AsmViz Browser-based x86-64 assembly visualizer built as a learning companion for Harvard CS61. Breaks down instructions, stack frame behavior, and control flow in AT&T syntax. Heuristic by design, not an emulator.
  • WinRefresh PowerShell tool that restores Windows 10 and 11 to a near-fresh state without reimaging: SFC and DISM repair, network stack reset, service and registry cleanup, restore point creation, and full logging.

Focus areas

  • Detection and threat hunting: ATT&CK-mapped detection engineering, SIEM content development, custom correlation and detection rules, time-series anomaly detection, analyst-facing dashboards
  • Incident response and investigation: incident lifecycle management, first response, coordination across corporate security, IT, legal, and third parties
  • Offensive security: penetration testing, network vulnerability assessment, enterprise vulnerability management programs
  • Cloud and identity: hybrid identity architecture, least-privilege app registrations, managed identities, IAM
  • Governance: NIST SP 800-53, FERPA, data classification, metadata schemas, lineage, data quality
  • Infrastructure: zero trust network architecture, infrastructure as code, CI/CD across Windows and Linux

Technologies I enjoy

Technology stack by layer. Governance: MITRE ATT&CK, NIST 800-53, Zero Trust, FERPA. Detection and response: Microsoft Sentinel, KQL, Splunk, Cortex XSIAM, CrowdStrike, Power BI. Offensive validation: Burp Suite, Qualys, Nessus. Identity and cloud: Entra ID, Microsoft Graph, Azure, AWS. Infrastructure: Terraform, Bicep, Docker, Red Hat, Linux. Build: Python, PowerShell, Bash, JavaScript, Flask, NumPy, MySQL, Git, GitHub Actions, Claude Code.

Background

Started September 2016 as a SOC analyst at AlphaServe Technologies: penetration tests, network vulnerability assessments, and physical security reviews. Moved to security operations at Jefferies as first responder for incidents across financial services infrastructure, running the enterprise vulnerability management program and coordinating investigations across corporate security, IT, legal, and third parties. Then senior security engineering at Educational Testing Service, leading NIST SP 800-53 implementation across cloud and on-premises systems and building KQL detection analytics, Sentinel workbooks, and ML-assisted anomaly detection using linear regression on time-series telemetry. Currently completing an M.A. in Cybersecurity at Harvard University, expected 2027.

Certifications

Microsoft Certified: Cybersecurity Architect Expert
SC-100
Cybersecurity Architect
2023
Microsoft Certified: Azure Security Engineer Associate
AZ-500
Azure Security Engineer
2023
Certified Information Security Manager
CISM
ISACA
2023
AWS Certified Security Specialty
AWS Security
Specialty
2020
Systems Security Certified Practitioner
SSCP
ISC2
2023
CompTIA PenTest+
PenTest+
CompTIA
2024
CompTIA CySA+
CySA+
CompTIA
2023
CompTIA Security+
Security+
CompTIA
2023
CompTIA Network+
Network+
CompTIA
2023
CompTIA Linux+
Linux+
CompTIA
2016
CompTIA A+
A+
CompTIA
2023
ITIL 4 Foundation
ITIL v4
Foundation
2020

Email

Popular repositories Loading

  1. Cortex-XSIAM Cortex-XSIAM Public

    XQL detection content and threat hunting queries for Palo Alto Cortex XSIAM: identity, endpoint, network, and Microsoft 365 coverage, plus XQL and XDR data model references.

    6 2

  2. AsmViz AsmViz Public

    Browser-based x86-64 assembly visualizer: instruction breakdown, stack frame behavior, and control flow in AT&T syntax. Built as a learning companion for Harvard CS61.

    JavaScript 1

  3. WinRefresh WinRefresh Public

    PowerShell tool that restores Windows 10 and 11 to a near-fresh state without reimaging: SFC and DISM repair, network stack reset, service and registry cleanup, restore points and logging.

  4. CS61_Notes CS61_Notes Public

    Study notes and reference material from Harvard CS61, Systems Programming and Machine Organization.

    JavaScript

  5. Dell_XPS Dell_XPS Public

    PowerShell diagnostics for Dell XPS hardware, including Find-PowerBleed for tracing idle power drain.

    PowerShell

  6. AbdallaElzedy AbdallaElzedy Public