20+ published security projects. A selection of the most relevant is below, with the full history onGitHub.
AD IAM Auditor
2026A modular Python tool that connects live to Active Directory via LDAPS and runs automated IAM security checks, generating timestamped audit reports.
- ▸Runs 4 automated checks: cross-department memberships, disabled accounts in active OUs, accounts with no groups, and 90+ day inactive accounts
- ▸Resolved 7 real technical blockers, including LDAP signing enforcement, LDAPS certificate binding, and Python 3.14's MD4 removal breaking NTLM auth (fixed via pycryptodome)
- ▸Generates professional PDF and HTML reports via reportlab and jinja2
- ▸Scanned 14 users against corp.local, surfacing 2 cross-department violations and 10 inactive accounts
PythonLDAPSActive Directoryreportlabjinja2
View on GitHub ↗Active Directory IAM Lab
2026A domain environment built from scratch to practice full identity lifecycle management and privilege auditing.
- ▸Deployed a Windows Server 2025 Domain Controller with 4 OUs and 3 RBAC security groups for domain corp.local
- ▸Provisioned 10 users via PowerShell and executed the full JML lifecycle: joiner, mover, and leaver
- ▸Ran a PowerShell access audit that caught cross-department privilege drift, documented with severity ratings and remediation steps
Windows ServerActive DirectoryPowerShellRBAC
View on GitHub ↗Wireshark Network Traffic Analysis Lab
May 2026Live packet capture and forensic analysis, including independent investigation of a real-world malware PCAP.
- ▸Applied 7 display filters to identify a 2,012-packet Nmap SYN scan, RST rejections, and plaintext HTTP exposure
- ▸Independently identified all 5 victim IOCs in a NetSupport Manager RAT PCAP via NBNS, Kerberos, and SAMR analysis
- ▸Produced a SOC-style incident report documenting C2 beaconing over TCP 443 with a full attack timeline
WiresharkPacket AnalysisMalware ForensicsMITRE ATT&CK
View on GitHub ↗Splunk SIEM Lab
2026SIEM deployment focused on SSH brute-force investigation, SPL query development, and incident documentation.
- ▸Ingested endpoint and authentication logs and hunted with SPL queries
- ▸Identified failed login patterns, off-hours authentication, and privilege escalation attempts
- ▸Documented findings in formal incident-report format
SplunkSPLSIEMThreat Hunting
View on GitHub ↗Wazuh EDR Homelab
2026An open-source EDR deployment across a multi-OS homelab for endpoint detection and compliance scanning.
- ▸Deployed Wazuh v4.7.5 across Parrot OS and Windows endpoints
- ▸Configured endpoint agents and triaged alerts for brute-force attempts and file integrity changes
- ▸Ran compliance scanning against endpoint baselines
WazuhEDREndpoint SecurityCompliance
View on GitHub ↗Python Security Automation Portfolio
2025 - Present18+ production-ready security automation tools spanning cloud security, threat detection, and network reconnaissance, aligned with Security+ domains.
- ▸S3 auditor with CRITICAL/HIGH/MEDIUM/LOW risk scoring targeting misconfigurations behind the Capital One breach
- ▸Concurrent TCP port scanner that covers 1,000 ports in 10 seconds, a 100x speedup over sequential scanning
- ▸3-layer brute-force detector (velocity, distributed IPs, account enumeration) and SHA-256 file integrity monitoring
PythonAWSboto3Network ReconAutomation
View on GitHub ↗