threat-intel2024 – 2025
DarkHuginn: Dark-Web Intelligence Platform
★ Founder · acquired by WhoMeta
Built end-to-end: automated Tor crawling pipelines discovering onion services, markets, and leak sites; blockchain-intelligence workflows tracing illicit wallets; OSINT enrichment linking indicators to open sources. Scaled on message queues and distributed workers.
PythonTorPostgreSQLDockerBlockchain APIs
platform2025 – 2026
Airgapped Kubernetes Security Platform
Designed WhoMeta's full foundation: Terraform IaC, AKS + self-hosted airgapped RKE2 HA clusters, private git and CI, registry with image signing and scanning, secrets management, SSO with multi-tenant realms, and end-to-end GitOps, all open-source on a startup budget.
TerraformRKE2ArgoCDHarborKeycloakcosign
detection2025 – 2026
SOC & Threat-Intelligence Program
Created WhoMeta's Security Operations Center from scratch: tooling, team, and process. Wazuh SIEM/XDR, TheHive case management, MISP threat intel, and real-time alerting wired into incident response, with intelligence collection feeding detection end-to-end.
WazuhTheHiveMISPGrafanaTrivy
detection2026
Enterprise SOC Build with AI-Driven Triage
Full detect-investigate-respond lifecycle for an enterprise client on an all-open-source stack: Wazuh, Security Onion (Suricata, Zeek, Arkime), Velociraptor DFIR, TheHive + Shuffle SOAR. An AI triage layer correlates and scores every alert so analysts only get paged for high-confidence incidents.
Security OnionZeekShuffleOpenCTILLM triage
offensive2025
Internal Penetration Test (Financial Services)
Authorized pentest of internal services for a European digital-asset trading and custody provider. Deep testing of authentication, access control (IDOR, privilege escalation), injection, and SSRF, with automated scanning verified manually so every finding carried demonstrable impact. Delivered CVSS-rated report and remediation retest.
Burp SuiteNmapNessusOWASPSQLmap
platform2026
One-Command K8s Platform Delivery (Enterprise)
23 modular Ansible roles that stand up a complete self-hosted security-intelligence platform for an enterprise client from bare hosts with zero manual steps: WireGuard hub, Keycloak SSO, 3-node RKE2 HA with Cilium, Longhorn, ArgoCD GitOps, self-seeding bootstrap, operable by a non-technical customer.
AnsibleCiliumWireGuardRancherCaddy
threat-intel2026
Tor Guard-Relay Intelligence Fleet
Productized the DarkHuginn appliance for a law-enforcement engagement: customer-shippable Ansible playbooks deploying a fleet of Tor guard-relay sensors with passive connection monitoring, per-relay databases, and an idempotent watermarked sync service merging the fleet into central analysis.
AnsibleGoTorsystemdGeoIP
platform2026
Zero-Downtime Dataplane Migration → Cilium/eBPF
Migrated a live 3-node production RKE2 cluster from Canal to Cilium with Hubble observability: 225 workloads, no data loss. Diagnosed stale eBPF state, VXLAN port conflicts, and CNI hostPort issues across three controlled iterations; re-architected ingress to hostNetwork.
CiliumeBPFHubblenginx-ingressLinux networking
detection2026 – present
Wazuh Ambassador: Detection-Engineering Research
★ Accredited Wazuh Ambassador
Published research with rule packs and tooling: Kubernetes hardening mapped to 7 compliance frameworks, closing kernel-level detection gaps with eBPF/Tetragon, catching Shadow AI via network telemetry, and detecting rogue MCP servers with MITRE ATT&CK-mapped rules.
WazuhTetragonHelmMITRE ATT&CKk3s
offensive2026 – present
Cyberdeck: Portable Security-Testing Rig
Two-part hardware platform for authorized lab use: Raspberry Pi + Kali base deck (Wi-Fi monitor/injection, dual RTL-SDR) remote-operated via Discord bot, plus an ESP32 handheld scanner. Includes a Wi-Fi pattern-of-life OSINT tool mapping BSSIDs against the WiGLE dataset.
ESP32Kali LinuxRTL-SDRWiGLE APIPython