Offensive security engagements, threat intelligence pipelines, SIEM/IDS implementations, honeypots, malware analysis, and automated DevSecOps static/dynamic scanning.
Conducted web application and network penetration testing across 20+ enterprise systems at ITS central IT services, uncovering critical vulnerabilities like SQLi, Broken Access Control, and request tampering.
An event-driven threat intelligence & security investigation platform in Go featuring Hexagonal Architecture, graph correlation, and an explainable 5-factor risk scoring engine.
All-in-One DevSecOps Scanner, Policy-as-Code Engine & Enterprise Security Orchestrator unifying SAST, DAST, SCA, Secrets detection, and automated AI remediation into a single binary.
Comprehensive attack data analysis from SNARE and TANNER web honeypots utilizing Frequent Pattern Mining, K-Means clustering, and statistical modeling to classify cyber attack behaviors.
A compilation of CTF writeups and solutions covering Web Exploitation, Cryptography, Reverse Engineering, Forensics, and PWN.
Deployed Wazuh SIEM to detect, analyze, and respond to malware execution, credential dumping, and web application attacks with automated VirusTotal threat intelligence enrichment.
Configured Snort Network Intrusion Detection System (NIDS) with community and custom rules to detect SYN scans, SQL injection, XSS, and LFI attacks with verified Proof-of-Concepts.
Deployed Cowrie (SSH) and SNARE & TANNER (Web) honeypots on AWS EC2 to capture real-world attacker telemetry, brute force attempts, payload downloads, and web exploitation patterns.
Automated Static Application Security Testing (SAST) using Semgrep and SonarQube across vulnerable fullstack apps (DVWA) and production Go APIs, auditing code quality and vulnerability remediation.
Automated Dynamic Application Security Testing (DAST) in CI/CD environments using OWASP ZAP-CLI against running web applications to identify runtime vulnerabilities and misconfigurations.
Dissected real-world malware samples and malicious Android APKs using static analysis (PE headers, Ghidra, hex inspection) and dynamic sandbox execution (Any.Run, VirusTotal).
Suite of custom penetration testing and reconnaissance scripts written in Python, including multi-threaded port scanners, SQL injection testers, and header fuzzers.