
r41n
•ProfileactiveOffensive security, web application security, Linux internals, detection engineering (Wazuh / auditd), and cloud security. Driven by the Build ➔ Break ➔ Observe ➔ Detect ➔ Document ➔ Improve methodology.
I am a Computer Science Engineering student working across offensive security, web security, systems internals, detection engineering, and cloud security.
The work focuses on understanding systems from both offensive and defensive perspectives—approaching cybersecurity not by merely collecting tools or memorizing vulnerability definitions, but by investigating how systems are built, how they fail under controlled exploitation, what telemetry attacks generate, and how security tooling can be engineered around those observations.
Operational Philosophy#
- Proof of Work Over Claims: Practical capability is demonstrated through reproducible laboratory environments, manual exploitation walk-throughs, and custom tooling rather than unsupported assertions.
- Defense Informed by Attack: Effective detection rules and hardened configurations require a fundamental mechanical understanding of exploitation primitives.
- Engineering-First Security: Emphasizing the ability to build security-related software and infrastructure from scratch rather than solely operating existing tools.
- Iterative Verification: Every finding, vulnerability test, and detection signature is validated against controlled targets before documentation.
Core Engineering Approach
BUILD
Deploy repeatable environments, services, and software architectures.
BREAK
Perform controlled manual exploitation to identify attack vectors and system failure modes.
OBSERVE
Capture endpoint activity, process lineage, system calls, and network traffic.
DETECT
Ingest telemetry into detection platforms (Wazuh, auditd) and author tuned rules.
DOCUMENT
Record root causes, reproduction steps, and defensive implications.
IMPROVE
Harden configurations, remediate vulnerabilities, and automate repeatable checks.
Technical Focus & Research Areas
Web Security
Manual OWASP Top 10 exploitation, payload crafting, root cause analysis
Linux Security
Internals, process lifecycle, permissions, endpoint telemetry, auditing
Windows / Active Directory
AD architecture, domain enumeration, attack paths, credential defense
Offensive Security
Controlled exploitation, privilege escalation, persistence, adversary emulation
Detection Engineering
Wazuh FIM/SCA, auditd event rules, process genealogy, attack-to-detection
Cloud Security
AWS IAM least-privilege scoping, cloud attack surfaces, misconfiguration analysis
Security Automation
Custom Python/TypeScript tooling, repeatable assessment workflows
Selected Projects
Persistence Hunter
›Defensive and endpoint security tool focused on identifying persistence mechanisms across operating systems.
PhishGuard
›Privacy-first ML phishing detection extension (Chrome MV3, Edge) & Flask backend evaluating Random Forest/CNN with explainability (Apache 2.0).
OWT Bandit
›Hands-on Linux command-line security exercises, shell scripting, permission escalation analysis, and terminal problem solving.
Practical Security Work
OverTheWire — Bandit
Levels 0 → 33 CompletedPractical foundational training covering Linux CLI navigation, multi-tier filesystem permissions, SSH configurations, shell pipes, process inspection, and text processing.
DVWA (Damn Vulnerable Web Application)
Manual OWASP Top 10Manual exploitation against intentionally vulnerable web application behaviors: SQL Injection, XSS, CSRF, Command Injection, File Inclusion, File Upload, and Broken Authentication.
PortSwigger Web Security Academy
Hands-on Labs CompletedPracticed manual vulnerability exploitation: Path Traversal, Unprotected Admin Functionality, Cookie Tampering, Privilege Escalation, Authentication Vulnerabilities, and Basic SSRF.
Controlled Security Tooling
Security UtilitiesHands-on usage of Burp Suite, Wazuh (Manager, Indexer, Dashboard, Agent), Auditd, Kali Linux, and Metasploitable in dedicated lab environments.
Lab & Homelab Infrastructure
Kali Linux (attack node) & Metasploitable (target node).
Wazuh Stack (Manager, Indexer, Dashboard, Agent) + auditd telemetry.
Tailscale encrypted mesh overlay & Nginx Proxy Manager.
Portainer for Docker orchestration & Netdata for live metrics.
Software & Systems Engineering Stack
Python, TypeScript, JavaScript, Bash, SQL
Next.js, React, React Native, Flask
Supabase, PostgreSQL, REST APIs
Docker, Git, GitHub, Vercel, Render, AWS
Practical Learning Progression
Documentation & Projects
Links & Profiles
Browse public repositories, research writeups, and resume.