Florian Roth Portfolio
Maintainer of Sigma, the open standard for writing SIEM detection rules (over 11,000 GitHub stars), plus signature-base and APTSimulator — a body of open-source detection engineering used across the SOC and threat-hunting community.
What makes it work
A breakdown of the choices that make this portfolio stand out.
An open standard, not just a personal tool
Sigma is a detection-rule format adopted broadly across the SIEM and SOC tooling ecosystem, not a one-off script — building shared infrastructure for an entire field is a rare and significant credential.
Multiple, complementary open-source projects around one theme
Sigma (detection rules), signature-base (YARA/IOCs), and APTSimulator (attack simulation) all address different angles of the same detection-engineering problem, showing a coherent research program rather than disconnected side projects.
Adoption visible through concrete numbers
Star and fork counts in the thousands across these repositories function as an inspectable adoption metric, doing more to establish credibility than any self-description could.
What Cybersecurity Analysts can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If you can generalize a personal tool into a shared format or standard others can adopt, that is a far stronger credential than a one-off script solving your own problem.
Build a family of related open-source projects around one theme rather than scattering unrelated repositories — coherence makes the body of work legible at a glance.
Let concrete, checkable numbers (stars, forks, downloads) demonstrate adoption instead of describing your tools as "widely used."
More Cybersecurity Analyst portfolios
Ready to build your portfolio?
Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.