Portfolio Material
This page collects selected evidence from my cybersecurity learning log. Each item is grounded in a real lab, implementation, or investigation, and written to show the judgement behind the work rather than just a list of tools.
The strongest themes so far are Linux access control, detection-quality tuning, secure automation design, artifact integrity, and the habit of validating a result independently before trusting it.
-
PASTA Threat Model: Sneaker Marketplace Mobile App
A practical PASTA threat-modeling exercise for a mobile sneaker marketplace, covering business objectives, architecture, data flows, threats, vulnerabilities, attack paths, and mitigations.
-
Vulnerability Assessment of an Internet-Exposed Database (Training Scenario, NIST SP 800-30)
A scenario-based assessment of a business-critical MySQL database reachable from the internet: risks identified and prioritised with NIST SP 800-30, plus remediation and validation steps. No live system was touched.
-
Letting Home Assistant Wake and Sleep a Mac Without Handing It Broad Access
Wake and sleep treated as two separate trust decisions: wake adds no new authority, and sleep goes through a local-only bridge that can run one fixed command.
-
Proving a Backup Restores: Encrypted Off-Host Backup of an Agent's State
An encrypted off-machine backup of my agent's database, verified by restoring it on a second machine and checking structure, contents and integrity.
-
Investigating an Unexplained Remote Shutdown and Locking Down the Power-Off Path
A Mac in my setup was powered off by a chat message with no clear cause. I traced the path that allowed it, closed it, and made shutdown default-deny with a record of every caller.
-
Building an SSRF Guard for an Agent's Web Fetches, Then Finding Two Bypasses in It
I built the guard that stops an agent tool fetching internal addresses, ran an independent review of my own fix, and found two live bypasses before either was patched.
-
Vetting Third-Party Tools Before Installing Them: Source, Permissions, Removal
How I evaluated candidate tools: pinned source revisions, comparison with a manual baseline, bounded trials, and clean removal for the ones that did not earn their place.
-
Stopping an AI Agent from Claiming Success It Cannot Prove
The verification layer around my agent supervisor: success needs evidence, checks fail closed, decision changes are shadow-tested, and recovery is rehearsed.
-
Sharing an Agent's Output Files Safely: Expiring Links and Hash Checks
A way to hand one task's report to one recipient without giving storage access: single-purpose expiring links, integrity checks before delivery, and durable delivery state.
-
Supervising an AI Agent: Approvals, Audit Logs and Recovery Before It Acts
I designed and tested a supervision layer for a local AI agent: task-scoped permissions, approvals, audit records and restart-safe controls. Feature-flagged and fixture-tested, not live.
subscribe via RSS
