What I build, break, and maintain.
A mix of automation, labs, and knowledge bases. Most of these started as "I keep doing this manually" and turned into something I could lend out to teammates.
# all
Project list
active
AutoSecOps
Opinionated pipeline that runs IaC, container, and secrets scanning on every PR and posts a single signal-to-noise report.
GitHub ActionsTrivySemgrepCheckov
active
Security Lab
Reproducible attack/defense lab: AD forest, Linux estate, vulnerable web apps, and replayable telemetry.
ProxmoxTerraformAnsibleSysmon
stable
Hardening Scripts
Idempotent PowerShell and Bash baselines for Windows servers, workstations, and common Linux distros.
PowerShellBashCISSTIG
research
Vulnerability Notes
Personal knowledge base mapping CVEs, attacker techniques, and the controls that actually break the chain.
ObsidianMITRE ATT&CKMarkdown
active
CTF Toolkit
Compact set of scripts and Dockerfiles I reach for during competitions — web, crypto, and pwn helpers.
PythonDockerpwntools