byteGirl_

~/CyberSecurity Projects

# 21 entries
File Integrity Monitoring (FIM) with Wazuh
20OK

$ File Integrity Monitoring (FIM) with Wazuh

Deployed Wazuh's syscheck for real-time file integrity monitoring over a Tailscale mesh, detecting unauthorized changes to critical files and directories through baseline comparison rather than signature matching.

WazuhXDRTailscaleFile Integrity Monitoring
[ Monitoring ][ Integrity ][ Endpoint Security ][ syscheck ]
Hardening macOS Against the CIS Benchmark with Wazuh
19OK

$ Hardening macOS Against the CIS Benchmark with Wazuh

A hands-on walkthrough of reading, understanding, and manually remediating CIS benchmark findings on macOS. No MDM required.

WazuhXDRTailscaleCIS BenchmarksApple
[ Monitoring ][ Compliance ][ Endpoint Security ][ Hardening ]
Centralized Security with Wazuh, Proxmox, and Tailscale
18OK

$ Centralized Security with Wazuh, Proxmox, and Tailscale

Deploying a Security Operations Center, monitoring my own infrastructure: a bare-metal hypervisor with Proxmox and cloud computing.

WazuhProxmoxSIEMTailscale
[ Monitoring ][ File Integrity ][ Endpoint Security ][ Hardening ]
Monitoring as a Security Control: UpTime Kuma
17OK

$ Monitoring as a Security Control: UpTime Kuma

Architected a secure external uptime monitoring pipeline using self-hosted Uptime Kuma on Proxmox, leveraging SQLite for minimal attack surface and out-of-band Telegram alerts to ensure availability detection independent of monitored infrastructure.

Uptime KumaProxmoxTelegram APIBOTs
[ Monitoring ][ Alerting ][ Resilience ][ Availability ]
Resilient Bulk Email: Subdomain Isolation with MailerLite
16OK

$ Resilient Bulk Email: Subdomain Isolation with MailerLite

Architected a bulk email infrastructure using subdomain isolation to protect primary domain reputation, with manually configured SPF, DKIM, and DMARC for full authentication control.

MailerLiteDNSSPFDKIMDMARC
[ Email Authentication ][ Reputation Management ][ Anti-Spoofing ]
Building a Technical Documentation Site with Zensical
15OK

$ Building a Technical Documentation Site with Zensical

Self-hosted technical documentation built with Zensical, a fast static docs generator full data ownership.

ZensicalMarkdownPythonHTTP server
[ Data Ownership ][ Documentation ][ Configuration ]
Penetration Testing: Validating My Infrastructure Against SQL Injection with Exegol & SQLMap
14OK

$ Penetration Testing: Validating My Infrastructure Against SQL Injection with Exegol & SQLMap

Offensive security simulation with SQL injection detection and vulnerability validation.

ExegolSQLMapOrbStackBash
[ Pentesting ][ SQL Injection ][ Ethical Hacking ]
DevSecOps: Automating Secure Deployments with GitHub Actions
13OK

$ DevSecOps: Automating Secure Deployments with GitHub Actions

Automated security gates with secure deployment and CI/CD integration.

GitHub ActionsNode.jspnpmSSHrsyncCI/CD
[ Security Gates ][ Secure Deploy ][ Least Privilege ]
Trivy Security Assessment
12OK

$ Trivy Security Assessment

Full-stack vulnerability scanning with secret detection and misconfiguration analysis.

TrivyDockerBash
[ Vulnerability Scanning ][ Secret Detection ][ CVSS ]
Secure Offsite Backups: Verification & Hardening
11OK

$ Secure Offsite Backups: Verification & Hardening

Defense-in-depth with brute-force protection and SFTP-only access enforcement.

SSH HardeningFail2BanUFWWireGuard
[ Defense-in-depth ][ Brute-force Protection ][ SFTP ]