Cybersecurity-focused builder with a growing interest in purple teaming, threat detection, and AI-assisted automation. The objective is to connect attacker tradecraft with defender visibility: emulate the threat, collect evidence, improve detections, and harden the system.
Purple-team principle: every offensive finding should become a defensive improvement.
┌──(adeen㉿purple-lab)-[~/security]
└─$ help
about operator profile and current focus
projects strongest security and AI projects
architecture system diagrams for featured tools
stack tools and technologies
contact collaboration and project feedback
┌──(adeen㉿purple-lab)-[~/security]
└─$ projects --featured
[01] ZTNA Self-Healing Network Architecture
[02] CyberShield SME
[03] Secure Distributed File System + AI Monitoring
[04] YARA Strings & Metadata Static Analyzer
┌──(adeen㉿purple-lab)-[~/security]
└─$ mission
detect → investigate → validate → automate → harden
Run a command
| Command | Output |
|---|---|
about |
Purple-team security builder focused on offensive validation, defensive visibility, and AI automation. |
projects |
Security tools spanning Zero Trust, passive reconnaissance, malware analysis, encrypted storage, and SOC workflows. |
architecture |
Scroll to the architecture lab below for system-level diagrams. |
stack |
Python, C++, TypeScript, Linux, Bash, Flask, React, Ollama, YARA, and Git. |
contact |
Open an issue or discussion in the relevant repository. |
The card below is updated daily by GitHub Actions from repository metadata and documented project capabilities. It is not a feed of live attacks or external threat-intelligence events.
This animated visual demonstrates the purple-team feedback loop: simulated security activity produces signals, the system correlates them, and defensive controls respond. It is intentionally a simulation, not live Internet attack data.
A NIST SP 800-207-aligned Zero Trust implementation that correlates ICMP, SYN, UDP-flood, port-scan, and DDoS signals; assigns per-IP trust scores; enriches events with local AI analysis and GeoIP context; and enforces response through iptables with watchdog re-verification. The project also includes an HTTPS SOC dashboard and HMAC-SHA256 audit logging.
An authorization-first, passive posture-assessment platform for small and medium businesses. It reviews HTTPS/TLS, selected headers and cookies, DNS, SPF, DMARC, MX, RDAP, certificate-transparency context, and public metadata; then produces deterministic A–F scoring, evidence-led reports, and AI-assisted remediation wording without letting the AI invent findings.
A seven-process local distributed file system with JWT-based Zero Trust authentication, AES-256-GCM encryption for file chunks, three-node replication, and detection coverage for brute force, ransomware, DDoS, and exfiltration patterns. A local Ollama agent performs root-cause analysis while the GRC dashboard maps security posture to NIST AI RMF, ISO 27001, and OWASP-oriented views.
A focused static-analysis workbench that combines YARA rules with MITRE ATT&CK mapping, string and metadata extraction, Shannon entropy, Base64 payload detection, weighted 0–100 threat scoring, a five-tab GUI, and PDF report export. The included samples are educational simulations rather than real malware.
For collaboration, purple-team experimentation, security research, or project feedback, open an issue or discussion in the relevant repository. The strongest work happens where offensive insight becomes measurable defensive progress.


