Lead Analyst: Dominic Nyongesa
Email: dominic.nyongesa@student.moringaschool.com
Operational Role: Junior / Mid SOC Analyst, Threat Hunter & Security Engineer
Institution: Moringa School Cyber Security Full Time
Standards: NIST SP 800-53 Rev. 5 | CIS Controls v8.1 | MITRE ATT&CK Enterprise Matrix v14 | FIRST CVSS v3.1
GitHub: @ngesa-cloud
Base Upstream Toolkits Re-Architected: WithSecureLabs/chainsaw & SigmaHQ/sigma
While legacy threat hunting tools such as WithSecure Chainsaw excel at static, offline analysis of Windows .evtx files, modern enterprise environments are intrinsically heterogeneous. Today's security operations teams must monitor Linux servers (Ubuntu/Debian, RedHat), Windows Domain Controllers, and container environments simultaneously.
Aegis-Hunter solves the three core architectural limitations of legacy hunting tools:
- Multi-OS Telemetry Ingestion: Natively parses and normalizes Linux auditd logs (
/var/log/audit/audit.log), auth.log/syslog, and Windows Security Event Logs (.evtx/ JSON). - Dynamic Sigma Rule Engine: Evaluates standard YAML Sigma detection rules with sub-second execution speeds without requiring complex external dependencies.
- AI-Driven Incident Triage & Correlation: Automatically groups isolated alert detections into chronological Adversary Attack Chains, computes contextual CVSS v3.1 scores, assigns strict SLA Containment Tiers (P1/P2/P3), and synthesizes production-ready NIST SP 800-53 remediation playbooks.
┌────────────────────────────────────────────────────────┐
│ Heterogeneous Telemetry Streams │
│ (Linux Auditd / Syslog Auth / Windows Security EVTX) │
└───────────────────────────┬────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────┐
│ Event Normalization Engine │
│ (Extracts Image, CommandLine, TargetFile, User, Host) │
└───────────────────────────┬────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────┐
│ Sigma Rule Detection Engine │
│ (Evaluates YAML Rules, Pattern Modifiers, Conditions)│
└───────────────────────────┬────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────┐
│ AI Threat Correlator & Triage Engine │
│ (Reconstructs Attack Chains, CVSS v3.1, MITRE Mapping) │
└───────────────────────────┬────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────┐
│ Multi-Format Incident Reporting │
│ (Rich ANSI CLI / Interactive HTML Dashboard / JSON/MD) │
└────────────────────────────────────────────────────────┘
python3 -m pip install pyyamlAnalyze authentic heterogeneous APT telemetry across an Ubuntu server (10.20.0.11) and Windows Domain Controller (10.20.0.10):
./aegishunt.py --demo# Scan Linux Auditd log against custom Sigma rules
./aegishunt.py --auditd /var/log/audit/audit.log --rules ./aegis/rules/
# Scan multi-OS artifacts and export an interactive HTML dashboard
./aegishunt.py \
--auditd /var/log/audit/audit.log \
--evtx ./windows_events.json \
--output-html ./output/incident_dashboard.html \
--output-json ./output/incident_report.json| Standard / Framework | Control / Technique ID | Operational Implementation in Aegis-Hunter |
|---|---|---|
| NIST SP 800-53 Rev. 5 | AU-6 |
Automated audit log review, cross-host correlation, and analysis. |
| NIST SP 800-53 Rev. 5 | IR-4 |
Automated incident handling and production-ready containment commands. |
| NIST SP 800-53 Rev. 5 | SI-4 |
Information system monitoring and malicious code behavior detection. |
| CIS Controls v8.1 | Control 8 |
Audit Log Management (Safeguards 8.2, 8.5, 8.11). |
| MITRE ATT&CK v14 | T1059 |
Execution: Unix Shell (T1059.004), PowerShell (T1059.001). |
| MITRE ATT&CK v14 | T1003 |
Credential Access: /etc/shadow (T1003.008), LSASS (T1003.001). |
| MITRE ATT&CK v14 | T1550 |
Lateral Movement: Pass-The-Hash via SMB Admin Shares (T1550.002). |
Run the automated test suite to verify ingestors, rule evaluation, and incident scoring:
python3 -m unittest discover -s tests -vDeveloped for academic research, authorized threat hunting, and defensive security operations within the Moringa School Cyber Security program. Unauthorized scanning or access against external systems is strictly prohibited.