SANS Cyber Academy - Scholarship Recipient 08/2025 β 05/2026
| Certification | Status |
|---|---|
| GIAC GCIH | β May 2026 |
| GIAC GSEC | β Feb 2026 |
| GIAC GFACT | β Nov 2025 |
| Sec Ops | API | Tools | Cloud | Networking | OS | VM | Programming |
|---|---|---|---|---|---|---|---|
| Incident response | NIST NVD | Splunk | AWS | TCP/IP | Linux | Ludus | JavaScript |
| Alert triage | Microsoft MSRC | Wazuh | Oracle Cloud (OCI) | DNS | macOS | Ansible | Python |
| Log analysis | Shodan | theHive | Azure AD | DHCP | Windows | Proxmox | Bash |
| Threat detection | VulnDB | Caldera | Cloudflare Workers | Packet analysis | qemu/virtio | Rust | |
| winRM | Metasploit | Cloudflare Durable Objects | Network hardening | Swift | |||
| Burp Suite | Firewall concepts |
| Event | Date | Result |
|---|---|---|
| SANS NetWars Core CTF | May 2026 | π₯ 2nd / 50+ |
| SANS CTF | March 2026 | π₯ 5th / 220+ in Veterans |
| AWS Γ SANS CTF | March 2026 | π₯ 32nd / 600+ |
| Snyk Annual CTF | February 2026 | π₯ 68th / 1,608 |
| SANS Holiday Hack Challenge | December 2025 | β 19 / 25 challenges completed |
- BSides Baltimore - April 2026
- SANS Community Night, MD - Feb 2026
- SANS Community Night, DC - Dec 2025
Building an end-to-end purple team environment with automated red team scenario generation and LLM-powered detection-as-code pipeline. Details coming soon.
Designed and implemented a defense-in-depth security stack for real-time audio streaming between an Apple Watch and a home server.
- Custom X.509 PKI enrollment workflow with mutual TLS (mTLS) - LAN-only enrollment tied to physical proximity
- AES-128-GCM encrypted UDP transport with cryptographic nonce derivation and replay protection via sequence numbers
- Certificate-based identity using the Apple Watch Secure Enclave (private key never leaves hardware)
- Three-port architecture separating enrollment, session auth, and media transport
- Integrated LangGraph AI assistant as the application layer
BunJS watchOS X.509 / mTLS AES-128-GCM UDP LangGraph
Deployed a cloud-based SIEM pipeline with secure log forwarding and automated rate-limit enforcement.
- Provisioned OCI free-tier instances with Tailscale ACL network segmentation
- Automated log collection pipeline:
rsyslogβrsyncβlogrotateβ Splunk Universal Forwarder - Built an OCI SDK shell script that monitors log volume and enforces API-based ingress lockdown to stay within Splunk's 500 MB/day free-tier limit
- Built SPL dashboards to visualize live SSH brute-force trends by source IP, geolocation, and daily occurrence rate
Splunk OCI Tailscale rsync rsyslog Bash OCI CLI



