Domain Specialty
Securing the
Untrusted Edge.
Implementing robust Zero-Trust architectures and real-time defense mechanisms. I specialize in identifying vulnerabilities, configuring deep packet inspection, and securing hardware interfaces before threats reach the network core.
Security Arsenal
Network Defense
- IDS/IPS Configuration
- Firewall Rulesets (MikroTik)
- Packet Analysis (Wireshark)
- DDoS Mitigation
Architecture
- Zero-Trust Networks
- VLAN Segmentation
- Edge Gateway Routing
- Cloud IAM Setup
Cryptography
- TLS / SSL Implementation
- Data-at-Rest Encryption
- JWT Auth Flows
- Secure Key Storage
Auditing & Testing
- Penetration Testing Basics
- Vulnerability Scanning
- Log Analysis
- Threat Modeling
Featured Defense System
Active Mitigation
IDS/IPS Edge Gateway
A custom-built Intrusion Detection and Prevention System deployed directly at the network edge on a Raspberry Pi 5. Engineered to inspect raw packets in real-time, instantly dropping malicious traffic before it hits internal servers.
Infrastructure
- • Raspberry Pi 5 Core
- • Promiscuous Mode Eth0
- • Hardened Linux Kernel
- • Isolated DMZ Setup
Logic & Rules
- • Snort IPS Rulesets
- • C/Python Scanners
- • Real-time IP Banning
- • Zero-Trust Verification
root@sec-gateway:~
███████╗██╗██████╗ ███████╗██╗ ██╗ █████╗ ██╗ ██╗
██╔════╝██║██╔══██╗██╔════╝██║ ██║██╔══██╗██║ ██║
█████╗ ██║██████╔╝█████╗ ██║ █╗ ██║███████║██║ ██║
██╔══╝ ██║██╔══██╗██╔══╝ ██║███╗██║██╔══██║██║ ██║
██║ ██║██║ ██║███████╗╚███╔███╔╝██║ ██║███████╗███████╗
╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝ ╚══╝╚══╝ ╚═╝ ╚═╝╚══════╝╚══════╝
_