Skip to content
View solomonneas's full-sized avatar

Sponsoring

@openclaw

Block or report solomonneas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
solomonneas/README.md

Yellow ๐Ÿ‘‹, I'm Solomon

I'm a Network & Systems Engineer / Teaching Lab Aid focused on cybersecurity, network observability, and AI infrastructure. I build SOC tooling, MCP servers, and agent workflows that run on real production gear, not toy demos. I write about it at solomonneas.dev/blog.

  • US flag US based in Tampa, FL, near the beach.
  • ๐Ÿ“œ M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
  • ๐Ÿ›ก๏ธ Building open-source SOC + threat intel tooling on bare-metal Proxmox.
  • ๐Ÿค– Deep in multi-agent orchestration, MCP servers, and detection engineering.
  • ๐Ÿชข n8n enthusiast, wiring up self-hosted automation for intel pipelines, monitoring, and SOC ops.
  • ๐Ÿงญ Currently exploring self-hosted AI stacks, network observability, and incident response automation.
  • ๐Ÿ“ Writing regularly on my blog, Dev.to, Hashnode, CoderLegion, and X.
  • ๐Ÿ—ฃ๏ธ Ask me about Proxmox migrations, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
  • โš™๏ธ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
  • ๐Ÿ‘จโ€๐Ÿ‘ง Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
  • ๐Ÿซถ If my work helped you, buy me a coffee or tip on Ko-fi.
  • ๐Ÿ“ซ Reach me at me@solomonneas.dev ยท LinkedIn ยท X

Some of the projects I've built or maintain:

OpenClaw & Dev Tools

  • ๐Ÿ” code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
  • ๐Ÿฆž solos-cookbook - Solomon's Guide to Cookin' with Gas: how one engineer runs a 24/7 multi-agent AI stack on bare metal. Opinionated. Dogfooded. Broken-and-fixed in production. Tested in service.
  • ๐Ÿณ solo-mise - Mise en place for the cookbook. One pipx install lays down the agent kitchen: 6 profiles (repo, workspace, openclaw, hermes, generic, publisher), content scrubber, handoff scaffolding, and a memory ingester. Everything in its place before you start cooking.
  • ๐Ÿ“Š usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
  • ๐Ÿ“š prompt-library - Dual-mode prompt management with browse/copy UI and a REST API for sub-agents.
  • ๐Ÿ›‚ content-guard - Policy-driven content scanning and publish checks.
  • ๐Ÿฉบ memory-doctor - Maintenance CLI for the Claude Code / OpenClaw memory system. Status, lint, ingest, and compact verbs with dry-run defaults, atomic writes, and path-safety on every mutation.

Security & Threat Intelligence

  • ๐Ÿ›ก๏ธ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
  • ๐Ÿ” bro-hunter - Threat hunting for Zeek and Suricata logs with beaconing detection and MITRE mapping.
  • ๐Ÿ”ฌ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
  • ๐Ÿ“– hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
  • ๐Ÿ—๏ธ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.

MCP Servers

  • ๐Ÿง  cortex-mcp - Observable analysis for IOCs, reports, and response actions.
  • ๐Ÿ›ก๏ธ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
  • ๐Ÿ”ฌ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
  • ๐Ÿ thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
  • โš”๏ธ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
  • ๐Ÿ”Ž zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
  • ๐Ÿฆ” suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
  • ๐Ÿ•ธ๏ธ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
  • โš™๏ธ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.
  • ๐Ÿ“ฎ postiz-mcp - Postiz social scheduling control with full public-API coverage, env-gated writes, and a 30/hr rate-limit guard.
  • ๐Ÿงฑ adguard-mcp - AdGuard Home control across one or more instances with 28 tools across read, safe-write, and destructive tiers: status + stats, query log, filter lists, user rules, client CRUD, blocked services, safesearch/safebrowsing toggles, query-log clear, stats reset. Three-tier confirm gates, basic-auth redaction, multi-instance env config.
  • ๐Ÿ–ฅ๏ธ proxmox-mcp - Proxmox VE control with 12 tools across read + safe-write tiers: status, container + VM lifecycle, snapshots, backups, recent tasks. Token auth, undici TLS-insecure dispatcher, multi-match ambiguity guard.
  • ๐Ÿ“ก librenms-mcp - LibreNMS network monitoring control with 10 tools: device + port + alert reads, port health rankings, alert ack, maintenance windows. Token auth, undici TLS-insecure dispatcher, LibreNMS spec format validation.

Network & Infrastructure

  • ๐Ÿ”ญ watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
  • ๐Ÿ”Œ portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
  • ๐Ÿ”’ proxguard - Proxmox firewall rule visualization with conflict detection and rule simulation.
  • ๐Ÿ“ถ eero-cli - Tiny CLI for the eero mesh API with non-interactive SMS auth, regex/MAC filtered device listing, and bulk blocking.
  • ๐Ÿง samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.

Media Automation

  • ๐Ÿ“บ media-cli - Single-file bash CLI for Sonarr, Radarr, Prowlarr, qBittorrent, Bazarr, Jellyseerr, and Tdarr.
  • ๐ŸŽฌ jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.
  • ๐ŸŽž๏ธ reelgrep - Local video search and analysis: ffprobe metadata, frame sampling, contact sheets, Whisper transcription, prose-transcript alignment, FTS5 subtitle search across the whole library, pluggable person-finding, and a local browser UI.
  • ๐Ÿ” reelgrep-mcp - MCP wrapper for reelgrep so agents can answer "which lecture mentioned X?" with citation-formatted timestamps from your local video library.

Streaming & OBS

  • ๐ŸŽ›๏ธ deckctl - Cross-platform declarative driver for the Elgato Stream Deck. One YAML config, hot reload, daemon for Linux + Windows, OBS execution + live state indicators, auto profile switching driven by the focused window. No Elgato app required.
  • ๐ŸŽฅ obsctl - kubectl-style multi-host wrapper around grigio/obs-cmd for managing OBS Studio across multiple machines from one CLI. Define hosts once, then obsctl studio recording toggle or obsctl laptop scene switch "Camera".

Currently Contributing To

  • ๐Ÿงƒ vincentkoc/tokenjuice - Lean output compaction for terminal-heavy agent workflows.
  • ๐Ÿ“ steipete/summarize - Fast summaries from URLs, files, and media. CLI + Chrome Side Panel + Firefox Sidebar with video slides, OCR, and transcript extraction.
  • ๐Ÿ“ฌ steipete/gogcli - Google Suite CLI for Gmail, Calendar, Drive, and Contacts.
  • ๐Ÿฆž openclaw/openclaw - Agent harness and CLI that runs my entire multi-agent stack on bare metal.
  • ๐Ÿฆž openclaw/plugin-inspector - Offline compatibility inspector for mocking OpenClaw and testing plugins.
  • ๐Ÿ”Œ openclaw/acpx - Headless CLI client for stateful Agent Client Protocol (ACP) sessions.
  • ๐Ÿ’ฌ steipete/discrawl - CLI for Discord with a SQLite backend.
  • ๐ŸŽญ microsoft/playwright - Cross-browser automation and testing framework, including the Playwright MCP server for agents.

I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.

Featured Writing

Infrastructure Migrations

SOC & Security Operations

Network Engineering

Agents & AI Infrastructure

Popular repositories Loading

  1. maltego-mcp maltego-mcp Public

    MCP server for authoring Maltego .mtgx graphs and running primitive OSINT lookups (whois/DNS/ASN/crt.sh). Composes with misp-mcp, thehive-mcp, and other security MCPs.

    TypeScript 4 1

  2. mitre-mcp mitre-mcp Public

    MCP server for MITRE ATT&CK knowledge base. Map alerts to techniques, profile threat groups, analyze detection gaps, and enrich SOC workflows with adversary intelligence.

    TypeScript 3

  3. wazuh-mcp wazuh-mcp Public

    MCP server for Wazuh SIEM platform integration (TypeScript)

    TypeScript 2

  4. rapid7-mcp rapid7-mcp Public

    MCP server for Rapid7 InsightIDR โ€” SIEM log search, investigations, alerts, UBA, and threat intelligence

    TypeScript 2

  5. proxguard proxguard Public

    Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts

    TypeScript 2

  6. solos-cookbook solos-cookbook Public

    How one engineer runs a 24/7 multi-agent AI stack on bare metal. Opinionated. Dogfooded. Broken-and-fixed in production. Tested in service.

    Shell 2