My background started in IT infrastructure, which led to a deeper interest in what actually happens inside a system during an attack. Most of my work now centers around malware analysis, offensive security, DFIR, and security engineering, with a focus on understanding malicious behavior through Windows internals, memory, network traffic, and endpoint telemetry.
My home lab is currently being rebuilt around RHEL, KVM/QEMU, libvirt, and containers, giving me a dedicated platform for isolated virtual machines, malware analysis, adversary simulation, and security services. Python is my primary language for building tools around log processing, IOC extraction, threat intelligence, and security automation.
| Project | Focus | Stack | Status |
|---|---|---|---|
| Malware Analysis Lab | Static and dynamic analysis, memory forensics, network analysis, isolated analysis infrastructure | RHEL, KVM/QEMU, libvirt, FLARE VM, REMnux, Volatility, YARA | |
| Windows Internals Lab | Processes, memory, persistence, telemetry, and forensic artifacts | Windows, Sysinternals, Sysmon, WinDbg, Volatility | |
| Sysmon Detection Lab | ATT&CK simulation, telemetry analysis, Sigma rules, and detection development | Sysmon, Sigma, Elastic, Wazuh, MITRE ATT&CK | |
| Log Normalizer / IOC Extractor | Log normalization, IOC extraction, suspicious pattern detection, structured output | Python, python evtx, regex, pytest | |
| Threat Intel Enricher | IOC enrichment, verdict scoring, threat intelligence pipelines | Python, VirusTotal, AbuseIPDB, PostgreSQL | |
| Enterprise Active Directory Lab | Domain administration, GPO, provisioning, and incident simulation | Windows Server, Active Directory, PowerShell | |
| SQL Security Lab | SQL injection, parameterized queries, RBAC, and row level security | Python, Flask, PostgreSQL | |
| Python Keylogger with C2 | Keystroke capture, encrypted collection, C2 communication, modular testing | Python, Flask, AES, pytest |
| Malware and DFIR | FLARE VM · REMnux · Volatility · YARA · Sysinternals · Wireshark |
| Offensive | Burp Suite · Nmap · Metasploit · Active Directory · MITRE ATT&CK |
| Detection | Sysmon · Sigma · Elastic · Splunk · Wazuh · Suricata |
| Infrastructure | RHEL · KVM/QEMU · libvirt · Podman · VMware · Proxmox · pfSense |
| Development | Python · PowerShell · Bash · SQL · Flask · PostgreSQL · pytest |
| M.S. Cybersecurity and Information Assurance | Western Governors University | 2027 (Expected) |
| B.S. Computer Information Technology | California State University, Northridge | 2026 |
| A.S. Cybersecurity and Computer Programming | Los Angeles Mission College | 2023 / 2024 |
Certified: CompTIA Security+ · CompTIA CySA+ · ISC2 CC In Progress: HTB CPTS · Cisco CCNA
Analyze the behavior. Understand the system. Build the detection.
