Skip to content

Navigation Menu

Sign in
Sign up
@ktf40858-stack
ktf40858-stack
Follow

Kodjo Apedoh ktf40858-stack

S-RankHunter πŸ† Elite Network Automation Engineer | Cisco Specialist | DevOps and Cybersecurity Enthusiast 🎯 S-Rank in network orchestration and automation

Block or report ktf40858-stack

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ktf40858-stack /README.md

Kodjo Apedoh

Network & Cloud Security Engineer
Arlington, Virginia Β· US Citizen Β· FranΓ§ais / English
Open to remote

LinkedIn TechVernia SankaraShield


I build network and security infrastructure from the ground up β€” routing, segmentation, firewall policy, secure remote access β€” then attack it, detect the attack, and audit the configuration that allowed it. Everything below is published: the configurations, the detections, the tooling, and the parts that do not work.

Focus on cloud-delivered security: SASE, firewall policy, detection engineering, and network automation in Python.

Certifications


Security engineering

Project What it is
network-config-compliance CI A Python tool that audits Cisco IOS configurations against CIS Benchmark and DISA STIG controls and fails a CI pipeline when a non-compliant configuration is about to ship. 16 tests, structured parser, three output formats.
soc-tier1-detection-lab A home SOC run end to end: Sysmon telemetry, six Sigma detections translated to Wazuh, each technique triggered on purpose with Atomic Red Team, then triaged with a written runbook. Mapped to MITRE ATT&CK, including the gaps.
l2-attacks-and-mitigations Six Layer 2 attacks β€” ARP spoofing, DHCP starvation, rogue DHCP, CAM overflow, VLAN hopping, STP takeover β€” each paired with the switch configuration that stops it and the capture that proves it.
palo-alto-segmentation-lab Zone-based segmentation on PAN-OS: least-privilege policy, App-ID instead of port rules, and East-West control between segments most networks leave flat.
fortigate-secure-remote-access FortiGate SSL VPN and IPsec IKEv2, built least-privilege β€” access tied to identity and role rather than a flat tunnel into the LAN.
zero-trust-sase-architecture Reference architecture for replacing perimeter VPN with identity-based access: NIST SP 800-207, ZTNA versus VPN, SASE, and a migration roadmap.

Network engineering

Lab What it demonstrates
Cisco NSO Network Automation Service orchestration across a multi-vendor estate β€” IOS, IOS-XE, IOS-XR and NX-OS β€” with device onboarding and service templates
Multi-Area OSPF Routing Two-site topology with redundant WAN links, authenticated OSPF adjacencies, QoS for voice and HSRP gateway redundancy
Enterprise Network Simulation Full enterprise build β€” VLANs, inter-VLAN routing, DHCP, NAT β€” with a hardened management plane and Layer 2 protections on every device
NAT Scenarios Static NAT, dynamic NAT, PAT, port forwarding and NAT Virtual Interface, with verification

No credential, key or real address appears in any of these repositories. Every configuration uses placeholders and documentation ranges (RFC 5737, RFC 1918), and the labs score 100% against the compliance tool above.


Working with


Writing

SankaraShield β€” networking and security: protocol behaviour, vendor releases, and what breaks in practice.

techvernia.com β€” hands-on technical reviews and guides, published in ten languages. 256 tools tested, 50+ guides.

Currently

  • Preparing CompTIA Security+
  • Extending the compliance tool to NX-OS and PAN-OS configurations
  • Publishing lab write-ups on SankaraShield

GitHub stats

Open to network and security engineering roles β€” remote, and the DC metro area.

Pinned Loading

  1. fortigate-secure-remote-access fortigate-secure-remote-access Public

    FortiGate SSL VPN and IPsec IKEv2 site-to-site built least-privilege: access tied to identity and role, not a flat tunnel into the LAN

  2. l2-attacks-and-mitigations l2-attacks-and-mitigations Public

    Six Layer 2 attacks (ARP, DHCP, CAM, VLAN, STP) with the switch configuration that stops each one and the capture that proves it

  3. network-config-compliance network-config-compliance Public

    Python tool that audits Cisco IOS configs against CIS Benchmark and DISA STIG controls and fails CI on non-compliant configuration

    Python

  4. palo-alto-segmentation-lab palo-alto-segmentation-lab Public

    Zone-based segmentation on Palo Alto PAN-OS: least-privilege policy, App-ID instead of port rules, and East-West control between segments

  5. soc-tier1-detection-lab soc-tier1-detection-lab Public

    Home SOC lab: 6 Sigma/Wazuh detections mapped to MITRE ATT&CK, Sysmon telemetry, Atomic Red Team validation and Tier 1 triage runbooks

  6. zero-trust-sase-architecture zero-trust-sase-architecture Public

    Reference architecture for replacing perimeter VPN with identity-based access: NIST 800-207 Zero Trust, ZTNA vs VPN, SASE and a migration roadmap

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /