Projects

Projects I’ve built while learning the craft.

Real sites, security experiments, and automation projects. Each one teaching me something new and pushing my skills forward.

Start a project
Designing an Azure Logging Pipeline for Control Plane Visibility
Azure Splunk Logging Detection Engineering Cloud Security Defensive Security

Designing an Azure Logging Pipeline for Control Plane Visibility

A hands-on project focused on designing and validating an Azure logging pipeline that provides real control plane and application-level visibility, with an emphasis on detection value, tradeoffs, and lessons learned.

Azure Monitor Azure Activity Logs Azure Event Hub Azure Functions Splunk Splunk HEC ngrok
Read case study
Cybersecurity Blog & Secure Azure Web Application
Cloud Security Azure Python Flask Docker Web Application Security WAF DevSecOps

Cybersecurity Blog & Secure Azure Web Application

A production-grade Python Flask web application deployed on Microsoft Azure, designed as both a secure content platform and a hands-on cloud security project. The site serves as a cybersecurity blog while demonstrating real-world deployment, monitoring, and application hardening practices.

Python Flask Docker Azure App Service Azure WAF Azure Security Center Microsoft Defender for Cloud Linux SSL/TLS
Read case study
LangChain Document Q&A Platform
LLMs LangChain FastAPI RAG Vector Databases AI Engineering Testing Full Stack

LangChain Document Q&A Platform

A full-stack document question-answering platform that allows users to upload PDFs or text files and ask natural-language questions using a retrieval-augmented generation (RAG) pipeline, with real-time responses and transparent source context.

Python FastAPI LangChain ChromaDB OpenAI API React Vite Tailwind CSS pytest LangSmith
Read case study
Hack The Box: Alert
Security Pentesting Hack The Box Web Exploitation XSS LFI Privilege Escalation

Hack The Box: Alert

An easy-rated penetration test focused on web application vulnerabilities, combining XSS, local file inclusion, credential cracking, and privilege escalation through insecure file handling.

Nmap FFUF Apache JavaScript Hashcat SSH Linux
Read case study
Hack The Box: LinkVortex
Security Pentesting Hack The Box Web Exploitation Git Docker Privilege Escalation

Hack The Box: LinkVortex

An easy-rated penetration test focused on modern web application weaknesses, including exposed Git repositories, CMS exploitation, and privilege escalation through insecure file handling.

Nmap Dirsearch FFUF Git-Dumper Ghost CMS Bash SSH
Read case study
Hack The Box: UnderPass
Security Pentesting Hack The Box Linux SNMP Privilege Escalation

Hack The Box: UnderPass

A medium-difficulty penetration test involving multi-protocol enumeration, credential discovery through exposed services, password cracking, and privilege escalation via a misconfigured sudo binary.

Nmap SNMP Gobuster Hashcat SSH mosh
Read case study
Hack The Box: Netmon
Security Pentesting Hack The Box Windows PRTG

Hack The Box: Netmon

A penetration testing walkthrough focused on enumeration through exposed services, credential discovery via backups, and exploitation of a known PRTG command injection vulnerability to achieve SYSTEM-level access.

Nmap FTP PRTG Network Monitor PowerShell Netcat tcpdump
Read case study
Hack The Box: Jerry
Security Pentesting Hack The Box Windows Tomcat

Hack The Box: Jerry

A hands-on penetration testing walkthrough focused on enumeration, credential abuse, and exploiting a misconfigured Apache Tomcat server to achieve full SYSTEM access.

Nmap Hydra Metasploit msfvenom Apache Tomcat Windows
Read case study
Defensive Log Monitoring & Detection Engineering
Defensive Security SOC SIEM Splunk Log Analysis Detection Engineering Incident Response

Defensive Log Monitoring & Detection Engineering

A defensive security project focused on monitoring Windows and Apache logs using Splunk, building baseline-driven alerts and dashboards, and analyzing attack activity through log correlation and behavioral deviation.

Splunk SPL Windows Security Logs Apache Logs Linux Security Onion Snort UFW
Read case study
Purple Team Nmap Automation
Security Purple Team Pentesting Network Scanning Automation IDS Defensive Monitoring

Purple Team Nmap Automation

A Purple Team security project focused on automating network reconnaissance with Python and Nmap, improving scan readability through XML-to-HTML transformation, and integrating scan output into defensive monitoring and detection workflows.

Python Nmap XSLT Linux Snort UFW Splunk Security Onion
Read case study