OPERATOR : Daniel Okwach Odhiambo
ROLE : Systems, Security & Software Engineer
FOCUS : Software Engineering · Network Infrastructure · SecOps & Forensics
CREDENTIALS: BSc Cybersecurity & Computer Networks · Cisco CCNA · Red Hat RH124 · ISC2 Candidate
I am an engineer working at the intersection of Software Development, Network Infrastructure, and Cybersecurity. I hold a BSc in Cyber Security & Computer Networks from Strathmore University, along with Cisco CCNA, Red Hat RH124, and ISC2 Candidate credentials.
I build reliable, secure, and deterministic systems across three core pillars:
- Software & Application Engineering: Architecting offline-first mobile applications on native Android (Kotlin, Jetpack Compose, localized SQLite / Room DB with defensive transactional migrations) and building automated data & telemetry pipelines.
- Systems Administration & Infrastructure: Administering multi-platform enterprise infrastructure across Linux (Red Hat RH124 v10.0, Ubuntu) and Windows Server, executing bare-metal deployments, and performing offline forensic disaster recovery (WinPE, DMDE, DISM) with zero data loss.
- Networking & Security Operations: Managing enterprise multi-site LAN/WAN routing and wireless AP deployments for 2,700+ concurrent users (Cisco CCNA), conducting network compliance audits that reduced vulnerabilities by 30%, and designing containerized SIEM threat detection pipelines (Wazuh, Elastic Stack) mapped to MITRE ATT&CK.
| Operational Domain | Core Technologies, Frameworks & Protocols |
|---|---|
| Threat Detection & SIEM | Wazuh SIEM · Elastic Stack (Elasticsearch, Logstash, Kibana) · IBM QRadar · MITRE ATT&CK · Custom Regex/XML Decoders · Syslog Forwarding · Alert Correlation & Tuning |
| Incident Response & Forensics | WinPE Offline Environments · DMDE Sector Analysis · MBR/GPT Partition Recovery · DISM Driver Injection · Offline Registry Hive Analysis · EVTX Event Log Analysis · Zero Data Loss Recovery |
| Security Hardening & Audits | Firewall ACL Enforcement · Port Security (802.1X) · VLAN Isolation & Subnet Hardening · Vulnerability Audits · Active Directory Security & GPO · Role-Based Access Control (RBAC) · Least Privilege Baselines |
| Network Infrastructure | Cisco CCNA · TCP/IP Architecture · VLAN 802.1Q & Trunking · OSPF & BGP Routing · Enterprise Wireless AP Deployment (100+ APs / 2,700+ Users) · Wireshark Packet Inspection · Multi-Site LAN/WAN · VOIP (Avaya) |
| Systems Administration | Red Hat Enterprise Linux (RH124 v10.0) · Ubuntu Linux · Windows Server Administration · Bare-Metal OS Deployment · Operational Runbooks · Disaster Recovery Planning |
| Software & Automation | Python (Automation & Scripting) · Bash / Shell · Kotlin (Native Android) · Jetpack Compose · SQLite / Room DB Integrity · REST APIs · Git · Docker |
🛰️ [ 01 ] WAZUH / ELASTIC STACK SIEM — TELEMETRY INGESTION & DETECTION
| Attribute | Specification |
|---|---|
| Project Type | Security Telemetry Architecture & Threat Detection Engineering |
| Operational Problem | Disconnected endpoint log sources and noisy raw syslog streams lead to analyst alert fatigue and delayed threat identification |
| Security Objective | Centralize endpoint threat detection, normalize incoming semi-structured logs, and map alerts directly to known adversary tradecraft |
| Architecture | Containerized Wazuh SIEM manager paired with Elastic Stack (Elasticsearch, Logstash, Kibana) and syslog forwarding pipelines |
| Detection Logic | Engineered custom regex decoders and XML log parsing rules mapped to MITRE ATT&CK techniques across host and network discovery (T1110 Brute Force, T1068 Privilege Escalation, T1098 Account Manipulation, T1083 File & Directory Discovery) |
| Operational Impact | Accelerated incident alert triage and reduced false-positive event volume by 40% |
| Key Insight | Accurate parsing at the ingestion layer is the foundation of high-fidelity detection; poorly normalized logs create noisy rules regardless of SIEM sophistication |
🛡️ [ 02 ] ENTERPRISE NETWORK SECURITY & COMPLIANCE AUDIT
| Attribute | Specification |
|---|---|
| Project Type | Enterprise Infrastructure Auditing & Network Hardening |
| Operational Problem | Multi-site enterprise infrastructure exhibited configuration drift, unhardened access paths, and unvalidated firewall rules across distributed subnets |
| Security Objective | Audit active network switches, validate TCP/IP routing tables, and enforce strict perimeter and internal access control policies |
| Environment | Multi-site production infrastructure, enterprise routing & switching hardware, perimeter firewalls |
| Methodology | Systematic inspection of routing tables, switch port security enforcement, subnet isolation, and Access Control List (ACL) compliance verification |
| Operational Impact | Eliminated identified network vulnerabilities by 30% and reduced infrastructure downtime by 40% through baseline hardening |
| Key Insight | Network segmentation and verified ACLs eliminate lateral movement attack paths before an adversary ever gains initial host access |
🔬 [ 03 ] OFFLINE DIGITAL FORENSICS & BARE-METAL PRODUCTION RECOVERY
| Attribute | Specification |
|---|---|
| Project Type | Enterprise Disaster Recovery & Production Forensics |
| Operational Problem | Mission-critical production workstations suffered severe kernel crashes and unbootable partition corruption with zero tolerated data loss |
| Security Objective | Conduct offline forensic analysis to identify root failure causes, repair compromised system states, and preserve critical operational artifacts |
| Forensic Toolkit | Offline WinPE preinstallation environment, DMDE sector & partition analysis, DISM driver injection, offline registry hive inspection |
| Resolution | Restored unbootable production workstations to 100% operational integrity with zero data loss; authored standardized runbooks cutting recurring escalations from ~15 to near-zero |
| Key Insight | Forensic preservation before intervention prevents irreversible corruption; understanding low-level partition and boot structures makes disaster recovery deterministic |
📱 [ 04 ] PESALYTICS — OFFLINE-FIRST ANDROID FINTECH APPLICATION ENGINE
| Attribute | Specification |
|---|---|
| Project Type | Live Mobile Application & Client-Side Database Engine |
| Operational Problem | Personal finance and SMS parsing applications frequently rely on third-party cloud backends, exposing sensitive financial metadata to cloud security risks |
| Security Objective | Architect a strictly offline-first, local-only transaction parser and personal analytics engine |
| Architecture | Kotlin, Jetpack Compose, localized SQLite / Room Database with strict transactional schema integrity and zero external telemetry leak |
| Codebase | github.com/DanielX8/Pesalytics-Budget-and-M-pesa-Tracker |
| Operational Impact | Multi-thousand lines of clean Kotlin delivering offline transactional integrity, defensive database migrations, and 100% data persistence across upgrades |
| Key Insight | Zero-trust data architecture begins by keeping sensitive transactional data entirely on client storage with cryptographic local integrity |
[ COMPLETED / CERTIFIED ] BSc Cyber Security & Computer Networks — Strathmore University (Second Class Upper)
[ COMPLETED / CERTIFIED ] Cisco Certified Network Associate (CCNA)
[ COMPLETED / CERTIFIED ] Red Hat System Administration I (RH124 v10.0)
[ COMPLETED / CERTIFIED ] AWS Academy Cloud Security Foundations
[ COMPLETED / CERTIFIED ] AWS Academy Cloud Foundations
[ ACTIVE / CANDIDATE ] ISC2 Candidate (2024 - 2027)
[ IN PROGRESS ] IBM QRadar SIEM Specialization (i3 Technologies IT Bootcamp)
[ QUEUED ] Advanced Threat Hunting & Cloud Security
> Root-cause investigation before intervention — preserving operational evidence and zero data loss is the baseline.
> Detection logic must be validated against real telemetry and adversary tradecraft (MITRE ATT&CK), not assumed from static rules.
> Network segmentation, VLANs, and firewall ACLs prevent lateral movement before an adversary establishes persistence.
> Operational runbooks and automation exist to eliminate cognitive fatigue and error, accelerating human decision-making.