I build security tools, forensic labs, and risk-aligned infrastructure on Linux. My work bridges two areas most people treat separately — technical security engineering and governance/compliance — by implementing the controls that frameworks like NIST CSF and ISO 27001 actually require, then documenting them the way a SOC or GRC team expects.
What I focus on:
- 🔵 Blue Team / Detection — HIDS, log analysis, alert automation, SOC tooling
- 🔬 DFIR — Network forensics, malware artifact analysis, packet-level threat reconstruction
- 📋 GRC & Controls — NIST CSF mapping, access control implementation, risk documentation
- 🐧 Linux Security — System hardening, daemon development, kernel-level tooling
| Repo | Domain | Description |
|---|---|---|
| ssh-bruteforce-lab | DFIR / GRC | SSH exploitation lab with MITRE ATT&CK mapping, CVSS scoring, NIST 800-53 & ISO 27001 alignment, and full remediation plan |
| Malware-analysis | DFIR | HawkEye keylogger kill-chain forensics — payload delivery, SMTP exfiltration, network artifact extraction |
| Network-Forensics-Case-Studies | DFIR / SOC | PCAP-based IR case studies: credential harvesting, TLS traffic triage, CLI-first tshark workflow |
| soc-analyst-env | Blue Team | OpenEnv RL environment simulating SOC L1 triage — 8-stage ATT&CK kill-chain generator, strict JSON action schema |
| Sentinel-FIM | Blue Team | Linux file integrity monitor — real-time watchdog, timestamped audit logs, daemon execution, NIST DE.CM aligned |
| HashGuard | Security Tools | HIBP k-anonymity password checker with entropy-based crack-time estimation and fortification suggestions |
| Ironclad-ID | Security Tools | RSA challenge/response identity system with hardware binding via Linux machine-id and forensic-grade secure deletion |
| Aegis-Vault | Security Tools | C++ encrypted local storage utility — confidentiality and integrity controls, CIA Triad applied |
Open to discussing threat detection, DFIR methodology, GRC frameworks, or security automation.
If my tools or labs have been useful, consider supporting the work.
