Domain Specialty

Securing the Untrusted Edge.

Implementing robust Zero-Trust architectures and real-time defense mechanisms. I specialize in identifying vulnerabilities, configuring deep packet inspection, and securing hardware interfaces before threats reach the network core.

Security Arsenal

Network Defense

  • IDS/IPS Configuration
  • Firewall Rulesets (MikroTik)
  • Packet Analysis (Wireshark)
  • DDoS Mitigation

Architecture

  • Zero-Trust Networks
  • VLAN Segmentation
  • Edge Gateway Routing
  • Cloud IAM Setup

Cryptography

  • TLS / SSL Implementation
  • Data-at-Rest Encryption
  • JWT Auth Flows
  • Secure Key Storage

Auditing & Testing

  • Penetration Testing Basics
  • Vulnerability Scanning
  • Log Analysis
  • Threat Modeling

Featured Defense System

Active Mitigation

IDS/IPS Edge Gateway

A custom-built Intrusion Detection and Prevention System deployed directly at the network edge on a Raspberry Pi 5. Engineered to inspect raw packets in real-time, instantly dropping malicious traffic before it hits internal servers.

Infrastructure
  • • Raspberry Pi 5 Core
  • • Promiscuous Mode Eth0
  • • Hardened Linux Kernel
  • • Isolated DMZ Setup
Logic & Rules
  • • Snort IPS Rulesets
  • • C/Python Scanners
  • • Real-time IP Banning
  • • Zero-Trust Verification
root@sec-gateway:~
███████╗██╗██████╗ ███████╗██╗ ██╗ █████╗ ██╗ ██╗
██╔════╝██║██╔══██╗██╔════╝██║ ██║██╔══██╗██║ ██║
█████╗ ██║██████╔╝█████╗ ██║ █╗ ██║███████║██║ ██║
██╔══╝ ██║██╔══██╗██╔══╝ ██║███╗██║██╔══██║██║ ██║
██║ ██║██║ ██║███████╗╚███╔███╔╝██║ ██║███████╗███████╗
╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝ ╚══╝╚══╝ ╚═╝ ╚═╝╚══════╝╚══════╝
_