M.Sc. Digital Forensics & Information Security - National Forensic Sciences University Blue-team & detection engineering · network forensics · detection-as-code
I build evidence-backed security tooling and contribute fixes to open-source blue-team platforms. Every project below ships with tests, CI, and reproducible evidence artifacts.
| Project | What it does | Stack |
|---|---|---|
| detfuzz | Evidence-backed detection-resilience testing for PowerShell/Sigma rules - safe mutations correlated against Sysmon telemetry, 98 unit tests, signed release | Python · pySigma · Sysmon |
| NetTrace | Offline malware-traffic analysis - PCAP parsing, beaconing/DGA detection, MITRE ATT&CK mapping, PDF reports. Validated on 12 real malware captures | Python · Scapy |
| soc-automation-lab | End-to-end SOC pipeline: Wazuh detection → n8n SOAR triage → VirusTotal → Velociraptor forensics, with an 18-case analyst casebook | Wazuh · n8n · Velociraptor |
| MalForge | Sandbox-report → detection-rule pipeline: Cuckoo/CAPE JSON → Sigma → Wazuh, with stable rule IDs and risk scoring | Python · Sigma |
| signalbudget | Cost-aware telemetry planning - Pareto frontier over ingest cost vs. hash-verified detection coverage | Python (zero-dep) |
| vigilant-api | Black-box API security scanner - OpenAPI-driven BOLA/IDOR/SSRF/JWT testing with forensic evidence output | Python · OpenAPI |
- Panther - fixed a Kubernetes IOC detection query (Snowflake clause ordering) · merged
- Wazuh - corrected RestrictAnonymous registry checks in Windows CIS policies
- IntelMQ - CSV formula-injection fix in spreadsheet exports
- IRIS · TheHive4py - session-handling fix / API documentation