~/CyberSecurity Projects
# 18 entries
$ Secure Offsite Backups: Restic + SFTP over WireGuard
Network isolation with encrypted tunneling and least privilege access design.
$ Secure Offsite Backups: Verification & Hardening
Defense-in-depth with brute-force protection and SFTP-only access enforcement.
$ Trivy Security Assessment
Full-stack vulnerability scanning with secret detection and misconfiguration analysis.
$ DevSecOps: Automating Secure Deployments with GitHub Actions
Automated security gates with secure deployment and CI/CD integration.
$ Penetration Testing: Validating My Infrastructure Against SQL Injection with Exegol & SQLMap
Offensive security simulation with SQL injection detection and vulnerability validation.
$ Building a Technical Documentation Site with Zensical
Self-hosted technical documentation built with Zensical, a fast static docs generator full data ownership.
$ Resilient Bulk Email: Subdomain Isolation with MailerLite
Architected a bulk email infrastructure using subdomain isolation to protect primary domain reputation, with manually configured SPF, DKIM, and DMARC for full authentication control.
$ Monitoring as a Security Control: UpTime Kuma
Architected a secure external uptime monitoring pipeline using self-hosted Uptime Kuma on Proxmox, leveraging SQLite for minimal attack surface and out-of-band Telegram alerts to ensure availability detection independent of monitored infrastructure.