Skip to content
View DanielX8's full-sized avatar
  • 13:56 (UTC +03:00)

Block or report DanielX8

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DanielX8/README.md
OPERATOR   : Daniel Okwach Odhiambo
ROLE       : Systems, Security & Software Engineer
FOCUS      : Software Engineering · Network Infrastructure · SecOps & Forensics
CREDENTIALS: BSc Cybersecurity & Computer Networks · Cisco CCNA · Red Hat RH124 · ISC2 Candidate

LinkedIn Email GitHub Pesalytics Profile Views


I am an engineer working at the intersection of Software Development, Network Infrastructure, and Cybersecurity. I hold a BSc in Cyber Security & Computer Networks from Strathmore University, along with Cisco CCNA, Red Hat RH124, and ISC2 Candidate credentials.

I build reliable, secure, and deterministic systems across three core pillars:

  • Software & Application Engineering: Architecting offline-first mobile applications on native Android (Kotlin, Jetpack Compose, localized SQLite / Room DB with defensive transactional migrations) and building automated data & telemetry pipelines.
  • Systems Administration & Infrastructure: Administering multi-platform enterprise infrastructure across Linux (Red Hat RH124 v10.0, Ubuntu) and Windows Server, executing bare-metal deployments, and performing offline forensic disaster recovery (WinPE, DMDE, DISM) with zero data loss.
  • Networking & Security Operations: Managing enterprise multi-site LAN/WAN routing and wireless AP deployments for 2,700+ concurrent users (Cisco CCNA), conducting network compliance audits that reduced vulnerabilities by 30%, and designing containerized SIEM threat detection pipelines (Wazuh, Elastic Stack) mapped to MITRE ATT&CK.

Operational Domain Core Technologies, Frameworks & Protocols
Threat Detection & SIEM Wazuh SIEM · Elastic Stack (Elasticsearch, Logstash, Kibana) · IBM QRadar · MITRE ATT&CK · Custom Regex/XML Decoders · Syslog Forwarding · Alert Correlation & Tuning
Incident Response & Forensics WinPE Offline Environments · DMDE Sector Analysis · MBR/GPT Partition Recovery · DISM Driver Injection · Offline Registry Hive Analysis · EVTX Event Log Analysis · Zero Data Loss Recovery
Security Hardening & Audits Firewall ACL Enforcement · Port Security (802.1X) · VLAN Isolation & Subnet Hardening · Vulnerability Audits · Active Directory Security & GPO · Role-Based Access Control (RBAC) · Least Privilege Baselines
Network Infrastructure Cisco CCNA · TCP/IP Architecture · VLAN 802.1Q & Trunking · OSPF & BGP Routing · Enterprise Wireless AP Deployment (100+ APs / 2,700+ Users) · Wireshark Packet Inspection · Multi-Site LAN/WAN · VOIP (Avaya)
Systems Administration Red Hat Enterprise Linux (RH124 v10.0) · Ubuntu Linux · Windows Server Administration · Bare-Metal OS Deployment · Operational Runbooks · Disaster Recovery Planning
Software & Automation Python (Automation & Scripting) · Bash / Shell · Kotlin (Native Android) · Jetpack Compose · SQLite / Room DB Integrity · REST APIs · Git · Docker

🛰️ [ 01 ] WAZUH / ELASTIC STACK SIEM — TELEMETRY INGESTION & DETECTION
Attribute Specification
Project Type Security Telemetry Architecture & Threat Detection Engineering
Operational Problem Disconnected endpoint log sources and noisy raw syslog streams lead to analyst alert fatigue and delayed threat identification
Security Objective Centralize endpoint threat detection, normalize incoming semi-structured logs, and map alerts directly to known adversary tradecraft
Architecture Containerized Wazuh SIEM manager paired with Elastic Stack (Elasticsearch, Logstash, Kibana) and syslog forwarding pipelines
Detection Logic Engineered custom regex decoders and XML log parsing rules mapped to MITRE ATT&CK techniques across host and network discovery (T1110 Brute Force, T1068 Privilege Escalation, T1098 Account Manipulation, T1083 File & Directory Discovery)
Operational Impact Accelerated incident alert triage and reduced false-positive event volume by 40%
Key Insight Accurate parsing at the ingestion layer is the foundation of high-fidelity detection; poorly normalized logs create noisy rules regardless of SIEM sophistication
🛡️ [ 02 ] ENTERPRISE NETWORK SECURITY & COMPLIANCE AUDIT
Attribute Specification
Project Type Enterprise Infrastructure Auditing & Network Hardening
Operational Problem Multi-site enterprise infrastructure exhibited configuration drift, unhardened access paths, and unvalidated firewall rules across distributed subnets
Security Objective Audit active network switches, validate TCP/IP routing tables, and enforce strict perimeter and internal access control policies
Environment Multi-site production infrastructure, enterprise routing & switching hardware, perimeter firewalls
Methodology Systematic inspection of routing tables, switch port security enforcement, subnet isolation, and Access Control List (ACL) compliance verification
Operational Impact Eliminated identified network vulnerabilities by 30% and reduced infrastructure downtime by 40% through baseline hardening
Key Insight Network segmentation and verified ACLs eliminate lateral movement attack paths before an adversary ever gains initial host access
🔬 [ 03 ] OFFLINE DIGITAL FORENSICS & BARE-METAL PRODUCTION RECOVERY
Attribute Specification
Project Type Enterprise Disaster Recovery & Production Forensics
Operational Problem Mission-critical production workstations suffered severe kernel crashes and unbootable partition corruption with zero tolerated data loss
Security Objective Conduct offline forensic analysis to identify root failure causes, repair compromised system states, and preserve critical operational artifacts
Forensic Toolkit Offline WinPE preinstallation environment, DMDE sector & partition analysis, DISM driver injection, offline registry hive inspection
Resolution Restored unbootable production workstations to 100% operational integrity with zero data loss; authored standardized runbooks cutting recurring escalations from ~15 to near-zero
Key Insight Forensic preservation before intervention prevents irreversible corruption; understanding low-level partition and boot structures makes disaster recovery deterministic
📱 [ 04 ] PESALYTICS — OFFLINE-FIRST ANDROID FINTECH APPLICATION ENGINE
Attribute Specification
Project Type Live Mobile Application & Client-Side Database Engine
Operational Problem Personal finance and SMS parsing applications frequently rely on third-party cloud backends, exposing sensitive financial metadata to cloud security risks
Security Objective Architect a strictly offline-first, local-only transaction parser and personal analytics engine
Architecture Kotlin, Jetpack Compose, localized SQLite / Room Database with strict transactional schema integrity and zero external telemetry leak
Codebase github.com/DanielX8/Pesalytics-Budget-and-M-pesa-Tracker
Operational Impact Multi-thousand lines of clean Kotlin delivering offline transactional integrity, defensive database migrations, and 100% data persistence across upgrades
Key Insight Zero-trust data architecture begins by keeping sensitive transactional data entirely on client storage with cryptographic local integrity

DanielX8 GitHub Streak



DanielX8 Contribution Heatmap

[ COMPLETED / CERTIFIED ]  BSc Cyber Security & Computer Networks — Strathmore University (Second Class Upper)
[ COMPLETED / CERTIFIED ]  Cisco Certified Network Associate (CCNA)
[ COMPLETED / CERTIFIED ]  Red Hat System Administration I (RH124 v10.0)
[ COMPLETED / CERTIFIED ]  AWS Academy Cloud Security Foundations
[ COMPLETED / CERTIFIED ]  AWS Academy Cloud Foundations
[ ACTIVE / CANDIDATE    ]  ISC2 Candidate (2024 - 2027)
[ IN PROGRESS           ]  IBM QRadar SIEM Specialization (i3 Technologies IT Bootcamp)
[ QUEUED                ]  Advanced Threat Hunting & Cloud Security

> Root-cause investigation before intervention — preserving operational evidence and zero data loss is the baseline.
> Detection logic must be validated against real telemetry and adversary tradecraft (MITRE ATT&CK), not assumed from static rules.
> Network segmentation, VLANs, and firewall ACLs prevent lateral movement before an adversary establishes persistence.
> Operational runbooks and automation exist to eliminate cognitive fatigue and error, accelerating human decision-making.

LinkedIn · Email · GitHub

Popular repositories Loading

  1. Pesalytics-Budget-and-M-pesa-Tracker Pesalytics-Budget-and-M-pesa-Tracker Public

    A privacy-first Android application built with Jetpack Compose for seamless MPESA transaction tracking, budget planning, and financial analytics.

    Kotlin 1 2

  2. pesalytics-web pesalytics-web Public

    Pesalytics coming soon site — offline M-PESA finance tracker for Android

    HTML

  3. Pesalytics-Website Pesalytics-Website Public

    TypeScript

  4. wazuh-elastic-siem wazuh-elastic-siem Public

    Enterprise SIEM architecture using Wazuh & Elastic Stack with automated Active Response threat mitigation, custom decoders, and MITRE ATT&CK mapping

    Python

  5. DanielX8 DanielX8 Public

  6. aegis-nis2 aegis-nis2 Public

    Autonomous Incident Triage, Automated Containment & EU NIS2 (Directive 2022/2555) Regulatory Compliance Engine

    Python