Projects
Security projects, and works I've built.
Nutanix Integration with SOC Fortress for Activity Monitoring and Visibility
Implemented an end to end SOC monitoring solution for Nutanix Prism Central logs using Graylog, OpenSearch, Grafana, and Python automation.
Active Directory Red Team Simulation with Wazuh Detection Engineering
An Active Directory red team assessment across a six phase attack chain, integrated with Wazuh SIEM for detection validation and rule tuning.
Production Wazuh SIEM Architecture and Infrastructure Automation
Distributed Wazuh 4.14.5 SIEM deployment across 13 VMs: a 3 node indexer cluster, server cluster with HAProxy load balancing, and mass agent deployment via Active Directory GPO and Ansible.
NetFlow Integration for Network Visibility and Detection Engineering
Network flow visibility integrated into Wazuh SIEM using pmacctd, Python normalization, and 24 custom detection rules validated against real internet traffic.
Endpoint Detection Engineering with Wazuh, Falco, Sysmon, and Auditd
Implemented Wazuh based security monitoring for Linux and Windows servers using Falco, auditd, and Sysmon, including custom detection development, validation, and production handover.