nesrine cherrabi

THREAT HUNTER

● Taking new engagements

Find out whether you're already compromised.

I run compromise assessments, write and tune the detection rules that keep the finding from repeating, and train teams to do the same in Elastic Security.

Top 2%

CyberDefenders worldwide · #2 in Algeria

OSTH

OffSec-certified threat hunter

3+

Years in MSSP SOC environments

hunt — session_04

nesrine@hunt:~$ hunt –hypothesis “credential access”

# querying endpoint telemetry across the estate…

[✓] baseline established

[!] anomaly: lsass.exe read by non-system parent

host FIN-WKS-07

technique T1003.001 OS Credential Dumping

tactic Credential Access

confidence high

# drafting detection rule + tuning threshold…

status: finding documented · rule shipped

What I do

Hunt for what your alerts missed, then make sure it fires next time.

Compromise assessment

Hypothesis-driven, MITRE ATT&CK-aligned threat hunting across endpoint, identity and network telemetry to answer one question: is there an adversary in here now, and was there one before?

Detection rules

Rule creation and tuning for Elastic Security, Splunk and EDR platforms. I audit what you can actually detect today, close the gaps, and cut the false positives behind alert fatigue.

Elastic Security training

Hands-on sessions for analysts and SOC teams: building queries, writing detection rules, and running structured hunts in Elastic. Practical labs, not slideware.

Retainer & on-call advisory

A recurring block of hunting and detection work, plus a responder to call when something looks wrong. Useful if you have telemetry but nobody whose full-time job is looking at it.

Who I work with

MSSPs & MSPs

Overflow hunting capacity and detection content for client estates.

In-house SOC teams

Coverage gaps, noisy rules, and hunts nobody has time to run.

Small & mid-size business

Security depth without hiring a full-time team.

Individual analysts

Elastic Security training and hunt mentoring, one to one.

Teams mid-incident

A second experienced set of eyes when something is already wrong.

Who you’re hiring

Certified where it matters, pragmatic everywhere else.

I’m Nesrine Cherrabi — a threat hunter working with teams that can’t justify a full-time SOC but still deserve the same rigor when something looks wrong. Three years across MSSP environments in Saudi Arabia and Algeria, now working with SOC teams across the MENA region and Europe — remote from GMT+1.

OffSec Threat Hunter

OSTH · OffSec

Formal hypothesis-driven hunting methodology, end to end — the certification this practice is built on.

Top 2%

CyberDefenders ranking

Top 2% worldwide on blue-team challenges — ranked #2 in Algeria.

IR

Incident Response

Infosec certified, 2023. Structured methodology from triage through recovery.

CAP

Certified AppSec Practitioner

The SecOps Group, 2023. Application security fundamentals.

DETECT.FYI

Published research

Author of “Alert Fatigue in SOCs: The Hidden Threat to Cybersecurity Efficiency”.

Before we talk

Straight answers to the usual questions.

Anything not covered here? The discovery call is free and there’s no pitch attached.

A time-boxed threat hunt across your existing telemetry to determine whether an adversary is active in your environment, or has been. You get documented findings mapped to MITRE ATT&CK, plus the detection gaps that let them go unnoticed.

Primarily Elastic Stack and Elastic Security, plus Splunk for SIEM work and CrowdStrike Falcon on the EDR side. Forensic analysis with Volatility and Wireshark.

Yes. Rule creation and tuning is a standalone engagement — I audit current coverage against ATT&CK, write high-signal rules, and tune the ones generating noise.

Remote sessions built around hands-on labs in your stack or a lab environment: query building, rule authoring, and running a structured hunt end to end. Scoped to your team’s level on the discovery call.

Least-privilege access, scoped to the engagement and documented. Evidence handling follows sound forensic practice so findings hold up if the matter becomes legal or insurance-related.

● Remote across MENA & Europe · GMT+1

Start with a 30-minute discovery call.

We talk through your environment, your telemetry, and what you actually need — assessment, detection work, training, or nothing at all.

Scroll to Top