● Taking new engagements
Find out whether you're already compromised.
I run compromise assessments, write and tune the detection rules that keep the finding from repeating, and train teams to do the same in Elastic Security.
Top 2%
CyberDefenders worldwide · #2 in Algeria
OSTH
OffSec-certified threat hunter
3+
Years in MSSP SOC environments
hunt — session_04
nesrine@hunt:~$ hunt –hypothesis “credential access”
# querying endpoint telemetry across the estate…
[✓] baseline established
[!] anomaly: lsass.exe read by non-system parent
host FIN-WKS-07
technique T1003.001 OS Credential Dumping
tactic Credential Access
confidence high
# drafting detection rule + tuning threshold…
status: finding documented · rule shipped
What I do
Hunt for what your alerts missed, then make sure it fires next time.
Compromise assessment
Hypothesis-driven, MITRE ATT&CK-aligned threat hunting across endpoint, identity and network telemetry to answer one question: is there an adversary in here now, and was there one before?
Detection rules
Rule creation and tuning for Elastic Security, Splunk and EDR platforms. I audit what you can actually detect today, close the gaps, and cut the false positives behind alert fatigue.
Elastic Security training
Hands-on sessions for analysts and SOC teams: building queries, writing detection rules, and running structured hunts in Elastic. Practical labs, not slideware.
Retainer & on-call advisory
A recurring block of hunting and detection work, plus a responder to call when something looks wrong. Useful if you have telemetry but nobody whose full-time job is looking at it.
Who I work with
MSSPs & MSPs
Overflow hunting capacity and detection content for client estates.
In-house SOC teams
Coverage gaps, noisy rules, and hunts nobody has time to run.
Small & mid-size business
Security depth without hiring a full-time team.
Individual analysts
Elastic Security training and hunt mentoring, one to one.
Teams mid-incident
A second experienced set of eyes when something is already wrong.
Who you’re hiring
Certified where it matters, pragmatic everywhere else.
I’m Nesrine Cherrabi — a threat hunter working with teams that can’t justify a full-time SOC but still deserve the same rigor when something looks wrong. Three years across MSSP environments in Saudi Arabia and Algeria, now working with SOC teams across the MENA region and Europe — remote from GMT+1.
OffSec Threat Hunter
OSTH · OffSec
Formal hypothesis-driven hunting methodology, end to end — the certification this practice is built on.
Top 2%
CyberDefenders ranking
Top 2% worldwide on blue-team challenges — ranked #2 in Algeria.
IR
Incident Response
Infosec certified, 2023. Structured methodology from triage through recovery.
CAP
Certified AppSec Practitioner
The SecOps Group, 2023. Application security fundamentals.
DETECT.FYI
Published research
Author of “Alert Fatigue in SOCs: The Hidden Threat to Cybersecurity Efficiency”.
- Assume breach, then prove it. A quiet environment isn’t evidence of safety — it’s a hypothesis to test.
- Signal over volume. A detection nobody trusts is worse than no detection. I tune for alerts your team will act on.
- Leave a paper trail. Every engagement ends with documentation both engineers and executives can read.
Before we talk
Straight answers to the usual questions.
Anything not covered here? The discovery call is free and there’s no pitch attached.
What is a compromise assessment?
A time-boxed threat hunt across your existing telemetry to determine whether an adversary is active in your environment, or has been. You get documented findings mapped to MITRE ATT&CK, plus the detection gaps that let them go unnoticed.
Which platforms do you work in?
Primarily Elastic Stack and Elastic Security, plus Splunk for SIEM work and CrowdStrike Falcon on the EDR side. Forensic analysis with Volatility and Wireshark.
Can you write detection rules without doing an assessment first?
Yes. Rule creation and tuning is a standalone engagement — I audit current coverage against ATT&CK, write high-signal rules, and tune the ones generating noise.
How does the Elastic Security training work?
Remote sessions built around hands-on labs in your stack or a lab environment: query building, rule authoring, and running a structured hunt end to end. Scoped to your team’s level on the discovery call.
How do you handle sensitive data and access?
Least-privilege access, scoped to the engagement and documented. Evidence handling follows sound forensic practice so findings hold up if the matter becomes legal or insurance-related.
● Remote across MENA & Europe · GMT+1
Start with a 30-minute discovery call.
We talk through your environment, your telemetry, and what you actually need — assessment, detection work, training, or nothing at all.