Independent builder / Naufal

Investigate systems.
Test ideas.

Machine Cyber Labs brings together my cybersecurity investigations and machine learning experiments. The next direction: a SOC triage assistant that turns sanitized evidence into clear, reviewable investigation notes.

Explore the product concept

The work behind the idea

Selected projects.

Six public projects.
Methods, code, and limitations included.

6 projects shown

01

Cybersecurity / Detection engineering

Windows SOC Detection Lab

A Windows and Sysmon telemetry pipeline into Splunk, with seven detections covering encoded PowerShell, failed logons, persistence, and misleading email attachment extensions.

  • Splunk SPL
  • Sysmon
  • PowerShell
Project notes

The lab is in progress. Gmail ingestion and scheduled alerts have been validated; continuous email polling has not been validated.

Repository
02

Cybersecurity / Incident investigation

Phishing Investigation Lab

Six training cases covering email headers and authentication, IOC extraction, attachment investigation, and evidence correlation with Splunk alerts.

  • SPF / DKIM / DMARC
  • IOC analysis
  • Splunk
Project notes

Cases use authorized simulations and lab-owned accounts. Reports distinguish simulated phishing from benign training email without claiming real compromise.

Repository
03

Cybersecurity / Purple team

SOC Purple Team Lab

Documented SSH/SFTP investigations, EDR detection validation, controlled process termination, scoped network isolation tests, and false-positive triage.

  • LimaCharlie
  • Wireshark
  • Sysmon
Project notes

Response exercises run on an owned VM. Documentation separates observed results, testing limitations, and capabilities that have not been implemented.

Read case SOC-L1-001
Repository
04

Machine learning / Computer vision

NeuroVision: Brain MRI Classification

A transfer learning experiment comparing ResNet50 and EfficientNetB0 across four MRI image classes, with per-class evaluation and a local web application.

  • PyTorch
  • ResNet50
  • EfficientNetB0
Project notes

A thesis research prototype. “No tumor” is a learned class; the application does not validate that an input is an MRI and has not been clinically validated for diagnosis.

Repository
05

Machine learning / Natural language processing

HoaxScan: Indonesian Text Classification

News text classification using TF-IDF, eight emotion features, and XGBoost. The Flask application supports training, evaluation, and individual or batch analysis.

  • XGBoost
  • TF-IDF
  • Flask
Project notes

Predictions do not independently verify claims. Documentation records duplicate texts across data splits that may overstate performance on unseen narratives.

Repository
06

Machine learning / Time series

Crude Oil Price Forecasting

An LSTM research application for forecasting oil closing prices using historical data and geopolitical risk indicators, with chronological splits and recorded evaluation.

  • TensorFlow / Keras
  • LSTM
  • pandas
Project notes

Recorded metrics measure one-step predictions. They do not measure recursive seven-step forecast accuracy or establish a causal benefit from geopolitical risk.

Repository

The person behind the work

Hi, I'm Naufal.

I explore cybersecurity through detection and investigation labs, and machine learning through classification and forecasting experiments.

Machine Cyber Labs is my independent project initiative and portfolio. I'm shaping the SOC assistant concept around the methods I've documented: preserve evidence, separate observations from assumptions, and make every conclusion reviewable.

Explore my GitHub