# projects

What I build, break, and maintain.

A mix of automation, labs, and knowledge bases. Most of these started as "I keep doing this manually" and turned into something I could lend out to teammates.

# all

Project list

active

AutoSecOps

Opinionated pipeline that runs IaC, container, and secrets scanning on every PR and posts a single signal-to-noise report.

GitHub ActionsTrivySemgrepCheckov
active

Security Lab

Reproducible attack/defense lab: AD forest, Linux estate, vulnerable web apps, and replayable telemetry.

ProxmoxTerraformAnsibleSysmon
stable

Hardening Scripts

Idempotent PowerShell and Bash baselines for Windows servers, workstations, and common Linux distros.

PowerShellBashCISSTIG
research

Vulnerability Notes

Personal knowledge base mapping CVEs, attacker techniques, and the controls that actually break the chain.

ObsidianMITRE ATT&CKMarkdown
active

CTF Toolkit

Compact set of scripts and Dockerfiles I reach for during competitions — web, crypto, and pwn helpers.

PythonDockerpwntools