I'm a cybersecurity practitioner who learns by doing. These projects cover the full defensive cycle: finding and fixing vulnerabilities, hunting for attackers in real telemetry, and turning what I find into detections. Each repository includes the queries, scripts, and evidence behind the work.
Across all of it I try to hold one standard: separate what the telemetry proves from what it can't show, and say which is which. "No evidence of exfiltration" and "no visibility into exfiltration" are different findings, and only one of them lets you close an incident.
- 🎓 Education: M.S. Cybersecurity and Information Assurance (WGU) · BBA in Management, University of Hawaiʻi at Mānoa (Shidler College of Business)
- 🛡️ Certifications: CompTIA CySA+, PenTest+, Security+ · ISC2 CC · Google Cybersecurity
- 🔎 Focus areas: threat hunting, incident response, detection engineering, digital forensics, vulnerability management
- 🛠️ Side project: building Rosterborn, a fantasy football app, with heavy AI assistance and mild stubbornness
- 🏃 Outside of work: running, volleyball, and taking fantasy football more seriously than is defensible. Vibe coding is the hobby now — mostly a retired gamer these days.
| Project | What it shows |
|---|---|
| TideGlass: AI Agent Intrusion Investigation | Traced an AI-agent attack across 8 log sources in Microsoft Sentinel, from exploit to AWS credential theft, lateral movement, and exfiltration of 2.8M customer records — 36 minutes from exploit to exfiltration, inside a 52-minute agent session. 28 findings with the 58 KQL queries behind them, MITRE ATT&CK and ATLAS mapping, 8 behavior-based detections, and an explicit account of what the telemetry could not establish. |
| Meridian: Healthcare Host Compromise | Full intrusion chain on a Linux healthcare web host — 18,454-request content discovery, file disclosure to credential reuse in 57 seconds, SUID root escalation (auid=1001, euid=0), and a confirmed patient-data export. Two findings beyond the chain: the incident was never contained, and the largest evidence gap was self-inflicted — the estate's own sweep removed Sysmon 39 minutes before the attacker arrived. |
| MySQL Ransomware — Honeynet Investigation | Real intrusion activity against a honeynet I built and instrumented. 12 external sources brute-forced an exposed MySQL service, enumerated every schema, issued 35 DROP statements, and left a Bitcoin ransom demand. Full timeline, IOC extraction with negative validation, and an explicit account of what the logs could not establish. |
| Cryptojacking via Spoofed Vendor Update | Three helpdesk tickets about a slow application traced to an XMRig miner on a file server, installed through a spoofed vendor email after Defender was disabled by Group Policy. Wazuh correlation, containment, and the detection gaps that cost five hours. |
| Project | What it shows |
|---|---|
| Endpoint Forensic Triage — Defender Live Response | Triage of a Windows 11 endpoint that surfaced an active Tor circuit — four established relay connections and a local SOCKS proxy, from a portable browser that left no uninstall entry. Four artifact classes corroborate it; decoded registry FILETIMEs reconstruct the download → extract → execute → connect chain to the second. |
| Project | What it shows |
|---|---|
| Sentinel SOC Visibility Workbooks | Four deployable Microsoft Sentinel workbooks turning Defender and flow telemetry into geographic triage views: inbound authentication origins, outbound C2 fan-in, exfiltration by byte volume, and allowed inbound traffic matched against threat intelligence. Commented KQL, deduplicated TI joins, companion grids for every map. |
| Project | What it shows |
|---|---|
| Risk-Based Vulnerability Management Program | A full scan → prioritize → remediate → verify cycle. Six remediation rounds took a Windows host from 2 Critical / 8 High / 12 Medium / 1 Low to 0 / 0 / 2 / 1 — 23 actionable findings down to 3, an 87% reduction — with the three remaining risks formally accepted and documented rather than suppressed. Ships the remediations as idempotent PowerShell, each script carrying the Tenable plugin ID it clears so the automation reconciles against the scan evidence. Includes API-driven Linux scanning. |
| Windows 11 DISA STIG Remediation | Ten idempotent, self-validating PowerShell scripts remediating Windows 11 STIG controls — three CAT I, plus Azure Trusted Launch with Secure Boot and vTPM. Each documents both the registry and Group Policy path and reads the value back to confirm it landed. Ships with a read-only compliance checker covering all ten. |
| Project | What it shows |
|---|---|
| Security Control Gap Assessments | Three assessments across healthcare, retail, and federal-contractor cloud migration. NIST SP 800-53 control ratings with the reasoning behind why two controls in the same family rate differently, PCI DSS and GDPR mapped to shared controls, and cloud security planning under an active audit deadline. |
🏅 Certifications
| Certification | Issuer | Year |
|---|---|---|
| CySA+ | CompTIA | 2026 |
| PenTest+ | CompTIA | 2026 |
| Certified in Cybersecurity (CC) | ISC2 | 2026 |
| Security+ | CompTIA | 2025 |
| Google Cybersecurity Certificate | 2025 | |
| Google Project Management Certificate | 2024 |
🗂️ Other repositories
| Repository | Contents |
|---|---|
| cyber-projects | Original submission reference for the STIG remediation scripts. Documented in full at Windows-11-STIG-Remediation. |
📫 Always happy to talk shop about detection engineering and incident response.
Connect on LinkedIn