homeprojectsblogabout
  • github

  • email

  • x / twitter

  • linkedin

  • personal docs

  • rss

© 2026 Yehezkiel Wiradhika

Cyber Security: Penetration Testing & DevSecOps

Offensive security engagements, threat intelligence pipelines, SIEM/IDS implementations, honeypots, malware analysis, and automated DevSecOps static/dynamic scanning.

DPTSI Penetration Testing
Internship

DPTSI Penetration Testing

Conducted web application and network penetration testing across 20+ enterprise systems at ITS central IT services, uncovering critical vulnerabilities like SQLi, Broken Access Control, and request tampering.

Cyber SecurityPenetration TestingBurp SuiteOWASP ZAPSQLMap
→
Vortex (Threat Intelligence Platform)
Custom Security Tool

Vortex (Threat Intelligence Platform)

An event-driven threat intelligence & security investigation platform in Go featuring Hexagonal Architecture, graph correlation, and an explainable 5-factor risk scoring engine.

Threat IntelligenceGoNext.jsMITRE ATT&CKVirusTotal
→
AegisCI
Custom Security Tool

AegisCI

All-in-One DevSecOps Scanner, Policy-as-Code Engine & Enterprise Security Orchestrator unifying SAST, DAST, SCA, Secrets detection, and automated AI remediation into a single binary.

DevSecOpsGoGitHub ActionsSASTDAST
→
Statistical, Frequent Pattern Mining and Machine Learning based Web Honeypot Attack Data Analysis: SNARE and Tanner
Thesis

Statistical, Frequent Pattern Mining and Machine Learning based Web Honeypot Attack Data Analysis: SNARE and Tanner

Comprehensive attack data analysis from SNARE and TANNER web honeypots utilizing Frequent Pattern Mining, K-Means clustering, and statistical modeling to classify cyber attack behaviors.

Machine LearningFrequent Pattern MiningWeb HoneypotsK-Means ClusteringCyber Security
→
Capture The Flags (CTFs)
CTF Writeups

Capture The Flags (CTFs)

A compilation of CTF writeups and solutions covering Web Exploitation, Cryptography, Reverse Engineering, Forensics, and PWN.

CTFCyber SecurityWeb ExploitationCryptographyBinary Exploitation
→
OS Security & Threat Monitoring (SIEM): Wazuh
Security Engineering

OS Security & Threat Monitoring (SIEM): Wazuh

Deployed Wazuh SIEM to detect, analyze, and respond to malware execution, credential dumping, and web application attacks with automated VirusTotal threat intelligence enrichment.

SIEMWazuhThreat DetectionSecurity EngineeringVirusTotal
→
Network & Web Attack Detection with Snort IDS
IDS / Security Lab

Network & Web Attack Detection with Snort IDS

Configured Snort Network Intrusion Detection System (NIDS) with community and custom rules to detect SYN scans, SQL injection, XSS, and LFI attacks with verified Proof-of-Concepts.

Network SecurityIDS/IPSSnortCustom RulesNmap
→
SSH and Web Honeypots using Cowrie and SNARE + TANNER
Threat Research

SSH and Web Honeypots using Cowrie and SNARE + TANNER

Deployed Cowrie (SSH) and SNARE & TANNER (Web) honeypots on AWS EC2 to capture real-world attacker telemetry, brute force attempts, payload downloads, and web exploitation patterns.

HoneypotCowrieSNARE & TannerThreat ResearchSSH Attacks
→
Web Security Static Analysis using Semgrep and SonarQube
DevSecOps

Web Security Static Analysis using Semgrep and SonarQube

Automated Static Application Security Testing (SAST) using Semgrep and SonarQube across vulnerable fullstack apps (DVWA) and production Go APIs, auditing code quality and vulnerability remediation.

SASTStatic Code AnalysisDevSecOpsSemgrepSonarQube
→
Web App Security Dynamic Analysis with OWASP ZAP-CLI
Security Testing

Web App Security Dynamic Analysis with OWASP ZAP-CLI

Automated Dynamic Application Security Testing (DAST) in CI/CD environments using OWASP ZAP-CLI against running web applications to identify runtime vulnerabilities and misconfigurations.

DASTDynamic AnalysisOWASP ZAPZAP-CLIWeb Application Security
→
Static & Dynamic Malware Analysis
Malware Analysis

Static & Dynamic Malware Analysis

Dissected real-world malware samples and malicious Android APKs using static analysis (PE headers, Ghidra, hex inspection) and dynamic sandbox execution (Any.Run, VirusTotal).

Malware AnalysisStatic AnalysisDynamic AnalysisPE ExplorerReverse Engineering
→
Custom Python Security Tools
Custom Security Tool

Custom Python Security Tools

Suite of custom penetration testing and reconnaissance scripts written in Python, including multi-threaded port scanners, SQL injection testers, and header fuzzers.

PythonSecurity ToolsPort ScannerSQLi ScannerMulti-threading
→