MalwareBazaar ThreatFox VirusTotal AbuseIPDB
I run live honeypot infrastructure that captures real-world malware, which I reverse, analyse and report to public threat intelligence feeds. My work covers the full loop — capturing and dissecting Linux malware, building detection with Wazuh, and documenting offensive techniques through hands-on writeups.
Focus: malware analysis · detection engineering · honeypot operations
Programming
Operating Systems
Debian Ubuntu Kali Linux Windows
Malware Analysis & Forensics
Static Analysis Reverse Engineering Volatility IOC Extraction MITRE ATT&CK YARA
Blue Team & Honeypot
Wazuh Cowrie SIEM Incident Response iptables OPNsense
Offensive Security
Nmap Gobuster OWASP ZAP Privilege Escalation Wireshark OWASP Top 10
DevSecOps & Infrastructure
Docker Vagrant GitHub Actions Snyk SonarCloud Gitleaks
Certifications
Fortinet NSE3 Google Cybersecurity FCF
| Repository | Description |
|---|---|
| threat-intelligence | Malware analysis reports and structured IOCs from honeypot captures. |
| honeypot | Multi-service honeypot with attacker scoring and automated C2 fetching. |
| wazuh-edr-deployment | Wazuh EDR deployment with automated active response. |
| pentest-writeups | Full-chain Linux compromise writeups with root cause analysis. |
| linux-hardening-lab | Vagrant lab: hardened SSH alongside a Cowrie honeypot. |
| devsecops-pipeline | CI/CD pipeline with Gitleaks, Snyk, SonarCloud and OWASP ZAP. |