Projects

Hands-on security engineering.

From an open-source financial-crime OSINT tool and a cloud SOC lab to custom CTF machines and offensive tooling — a sample of the work I build and break.

Security engineering

Offense, defense & labs.

Aug 2024 – Present

Microsoft Sentinel SIEM & SOC Lab

A cloud SOC lab in Azure with Microsoft Sentinel — data connectors, KQL detections, incident triage, and automated response playbooks for real-time threat detection.

AzureSentinelKQLEntra IDMITRE ATT&CK
Independent research

Vulnerability & Bug-Bounty Research

Testing across REST and GraphQL: 30+ findings including GraphQL admin takeover, IDOR, and 18+ XSS from outdated JavaScript modules — each paired with remediation.

Burp SuiteGraphQLInQLAltairOWASP
Woz U capstone

The Office: Doomsday Device CTF

A boot-to-root CTF machine I built with multiple solution paths — steganography, metadata, and privilege escalation — plus a full annotated walkthrough.

NmapGobusterHydraExifToolWireshark
Sandbox

CTF Vulnerable Machine

A penetration-testing sandbox using audio/visual steganography, Morse, PGP, and image-metadata exfiltration, with multiple ways to solve each flag.

SteganographyPGPSQLiPHP

Want the details behind any of these?

Start a conversation →