Flagship / Open Source XDR
PublicAegis Fortress XDR
Open-source, kernel-native XDR concept for critical infrastructure, combining endpoint, network, cloud, identity, detection, SOAR, and deception layers in one documented architecture.
Case File 04 — Work
My portfolio includes product work, defensive security systems, kernel research, open-source experimentation, and the structured methodology I use when evaluating a system under realistic conditions.
Project Index / 2026
Filter the archive by the type of work that interests you. Each entry links to a more detailed case study, a live product, or the public repository where the work is documented in context.
Showing all 12 projects
GitHub Shelf
These repositories reflect the kinds of systems I am actively exploring: defensive engineering, kernel-level security research, eBPF experimentation, and honest project work that is still evolving as I learn and improve it.
Flagship / Open Source XDR
PublicOpen-source, kernel-native XDR concept for critical infrastructure, combining endpoint, network, cloud, identity, detection, SOAR, and deception layers in one documented architecture.
Kernel Research
PublicLinux kernel module research exploring Ring 0 stealth mechanics, VFS and network visibility manipulation, symbol resolution, and the forensic signals defenders can use to detect them.
Kernel-Native EDR
PubliceBPF-LSM endpoint defense focused on deterministic pre-execution enforcement, process lineage reconstruction, and automated forensic stasis after a policy violation.
eBPF / Rust EDR Agent
PublicLinux EDR agent using eBPF tracepoints and a Rust control plane to monitor sensitive file access, intervene on violations, and send real-time telemetry.
Autonomous Defense Lab
PubliceBPF-LSM EDR research combining kernel-enforced blocking, automated containment, a Streamlit SOC dashboard, remote telemetry collection, and a chaos-testing suite.
New Repository
SetupA newly created public repository currently without committed files. Kept visible as a transparent placeholder for the next security project.
Featured Projects
The two current flagship repositories: one broad defensive platform and one focused kernel-native enforcement system.
Flagship Security Platform
PublicAn open-source XDR architecture for critical infrastructure, spanning kernel-native endpoint visibility, industrial network telemetry, cloud and identity logs, AI-assisted detection, SOAR response, and deception technology.
Kernel-Native Endpoint Defense
PublicAn eBPF-LSM EDR system designed to stop unauthorized execution at the Linux kernel boundary, reconstruct process lineage, and preserve forensic artifacts through a veto–freeze–carve workflow.
Full-Stack Developer
ShippedFinancial management platform for micro, small, and medium enterprises, focused on data handling practices and a clean, accessible interface for non-technical owners.
Self-Built, Deliberately Vulnerable API
ShippedA hands-on environment simulating real-world vulnerability classes, including IDOR, broken authentication, and injection points, built to refine testing methodology in a controlled sandbox.
Personal Tooling, Early Stage
In ProgressA toolkit automating the initial reconnaissance phase of security testing, focused on subdomain enumeration and endpoint discovery. Built as the primary vehicle for learning Go.
Reference Implementation
ShippedAuthentication using React and Firebase Auth, implementing email verification and secure session handling. Used as a reference for smaller projects that do not warrant a fully custom auth layer.
Case Study
C-Pay: closed-loop payment architecture, from problem to honest scope.
The Problem
Campus events at my university handled payments with cash, which created two recurring issues: reconciliation errors at the end of each event, and no audit trail when disputes came up about what a student had or had not paid. C-Pay replaces that with a closed-loop digital wallet system specific to campus events.
System Architecture
+------------------------------------------------------------+
| CLIENT (React) |
| Event Check-in UI . Wallet Balance View . Merchant Terminal |
+---------------------------+----------------------------------+
| HTTPS / REST
+---------------------------v----------------------------------+
| API LAYER (Express.js / Node.js) |
| Auth Middleware | Transaction Controller | Input |
| (session/token) | | Validation |
+---------------------------+----------------------------------+
|
+---------------------------v----------------------------------+
| DATABASE (MongoDB) |
| Users/Wallets Collection . Transactions Ledger . Event Data |
+------------------------------------------------------------+
Design Decisions
What I'd Change
Add automated integration tests around the transaction controller specifically, since that is the highest-consequence code path and currently relies on manual testing before each deployment. Add rate limiting on the transaction endpoints, which was not implemented in the first version.
Honest Scope Note
C-Pay was built and used for campus events, not deployed as a commercial payment processor and not handling real-world transaction volume at scale. What it demonstrates is the ability to own a complete system, including the security-conscious decisions above, from schema to shipped product.
Security Methodology
A repeatable five-step process, developed through the university-recognized assessment and a self-built pentesting lab.
Code Sample
Ownership-checked, fail-closed middleware, a representative pattern used across C-Pay to prevent IDOR on wallet and transaction routes.
// middleware/verifyOwnership.js
const verifyOwnership = (Model, paramField = 'id') => {
return async (req, res, next) => {
try {
const resource = await Model.findById(req.params[paramField]);
if (!resource) {
return res.status(404).json({ error: 'Resource not found' });
}
// Fail closed: only the authenticated owner may proceed
if (resource.userId.toString() !== req.user.id.toString()) {
return res.status(403).json({ error: 'Forbidden' });
}
req.resource = resource;
next();
} catch (err) {
next(err);
}
};
};
module.exports = verifyOwnership;