I work across system administration, infrastructure, networking and defensive security, with a strong focus on automation, security hardening, detection, monitoring and reproducible technical workflows.
My GitHub portfolio contains practical projects built around real-world system administration and cybersecurity scenarios — from Active Directory security assessment and incident triage to network segmentation, detection engineering and infrastructure automation.
I use AI-assisted development workflows to accelerate implementation, testing, documentation and CI/CD, while keeping technical validation and final decisions human-reviewed.
- Windows & Active Directory administration
- Linux & Ubuntu Server
- Network architecture and segmentation
- Defensive security and system hardening
- Detection Engineering & Sigma
- Incident Response & DFIR
- Docker and container security
- Infrastructure automation with Ansible
- PowerShell, Python and Bash automation
- GitHub Actions and CI/CD
- Virtualization with Proxmox
- Firewalling and network security with OPNsense
Network security architecture, device classification and interactive topology
Privacy-first network segmentation lab focused on:
- network segmentation and security zones
- explainable device classification
- quarantine workflows
- reachability and policy analysis
- synthetic network simulation
- RADIUS-based network access concepts
- interactive 3D network topology
- wired, wireless and logical network visualization
Tech: Python · React · TypeScript · Three.js · Networking · RADIUS · Cybersecurity
Detection-as-Code and SOC-oriented security engineering
Offline detection engineering lab for developing and validating original Sigma detections.
Includes:
- original Sigma rules
- synthetic behavioral testing
- MITRE ATT&CK mapping
- detection coverage analysis
- positive and negative test cases
- pySigma query conversion
- SIEM-oriented workflows
- automated validation
Tech: Python · Sigma · MITRE ATT&CK · Pytest · Splunk · Elasticsearch · PowerShell
Read-only Active Directory security assessment
PowerShell-first security auditing toolkit covering:
- privileged access
- Kerberos security
- Windows LAPS
- Group Policy
- Active Directory ACLs
- security posture assessment
- offline configuration drift analysis
Designed around defensive, minimally invasive and reproducible assessment workflows.
Tech: PowerShell · Active Directory · Windows Server · Kerberos · Group Policy · Pester
Infrastructure-as-Code and configuration management
Infrastructure automation lab built around reusable Ansible roles and repeatable configuration management.
Includes:
- reusable roles
- automated server configuration
- Ansible check mode
- configuration drift reporting
- idempotence validation
- Molecule testing
- GitHub Actions CI
Tech: Ansible · Linux · YAML · Jinja2 · Molecule · GitHub Actions
Cross-platform DFIR and evidence collection
Defensive incident-response toolkit designed for minimally invasive endpoint triage.
Features include:
- evidence collection
- integrity verification
- UTC timeline generation
- structured reporting
- privacy-aware workflows
- cross-platform support
Tech: Python · PowerShell · Bash · DFIR · Incident Response · Pytest
Docker security analysis and policy-as-code
Offline security analyzer for Docker Compose and Dockerfile configurations.
Includes:
- security baseline checks
- policy-as-code
- secret-safe reporting
- security scoring
- SARIF output
- proposed remediation guidance
- automated testing
Tech: Python · Docker · Docker Compose · Dockerfile · Pytest · SARIF
Passive network-device inventory, classification and event detection with privacy-aware reporting.
Hardening, auditing and operational security for Linux GitHub Actions self-hosted runners.
Cross-platform backup freshness, integrity, archive-safety and restore-readiness verification.
Read-only Windows system health assessment and automated JSON/HTML reporting.
Windows Windows Server Active Directory Linux Ubuntu Server
Proxmox OPNsense Docker
TCP/IP VLANs Network Segmentation Firewalling
RADIUS Network Monitoring
Security Hardening Security Auditing DFIR Incident Response
Detection Engineering Sigma MITRE ATT&CK Container Security
PowerShell Python Bash Ansible YAML
Git GitHub Actions CI/CD Pytest Pester Molecule
Across my projects I focus on:
- Read-only or minimally invasive operation where possible
- Reproducible and automated testing
- Defensive and authorized security use
- Structured and machine-readable reporting
- Privacy-aware data handling
- Explicit handling of uncertainty and inferred data
- Configuration validation and drift detection
- CI/CD-based quality gates
- Clear documentation and reproducible environments
- Separation between collection, analysis and decision-making
I use AI-assisted development as part of my engineering workflow for:
- implementation support
- test generation and expansion
- code review assistance
- documentation
- CI/CD workflow development
- troubleshooting and iterative validation
AI is used as an engineering accelerator, while architecture decisions, security assumptions, testing and final validation remain human-controlled.
I'm continuing to deepen my skills across:
System Administration · Cybersecurity · Blue Team · Infrastructure Security · Automation · Detection Engineering · DevSecOps