Hands-on security engineering.
From an open-source financial-crime OSINT tool and a cloud SOC lab to custom CTF machines and offensive tooling — a sample of the work I build and break.
Investigations & OSINT.
Offense, defense & labs.
Microsoft Sentinel SIEM & SOC Lab
A cloud SOC lab in Azure with Microsoft Sentinel — data connectors, KQL detections, incident triage, and automated response playbooks for real-time threat detection.
Vulnerability & Bug-Bounty Research
Testing across REST and GraphQL: 30+ findings including GraphQL admin takeover, IDOR, and 18+ XSS from outdated JavaScript modules — each paired with remediation.
The Office: Doomsday Device CTF
A boot-to-root CTF machine I built with multiple solution paths — steganography, metadata, and privilege escalation — plus a full annotated walkthrough.
CTF Vulnerable Machine
A penetration-testing sandbox using audio/visual steganography, Morse, PGP, and image-metadata exfiltration, with multiple ways to solve each flag.
Tools & utilities.
Acronomicon
A cybersecurity acronym quiz to help learners drill security and certification terminology for quick recall.
creedGEN
A themed wordlist generator that produces targeted lists for brute-force tools like Hydra against CTF scenarios.
cyberPUNKED
A network discovery and enumeration script in the spirit of netdiscover and arp-scan, with added functionality.