Flagship · SIEM · SOAR · Detection Validation
Custom SIEM + Sentinel BAS
A full detection-and-response platform built from scratch in Python, paired with a Breach & Attack
Simulation engine that validates whether detections actually fire against live attack simulations.
PUBLIC GITHUB REPO ↗
35Correlation-based detection rules
SigmaYAML detection engine support
70%Documented BAS run coverage: 7 detected / 3 missed
3 rolesViewer / Analyst / Admin RBAC
Detection & Response Platform
Mini SIEM
Multi-source ingestion across Windows Event Log, Linux syslog, Sysmon and remote Windows forwarders,
with attack-chain correlation, case management, threat hunting, SOAR workflows and AI-assisted incident summaries.
Detection Validation Engine
Sentinel BAS
Drives Atomic Red Team techniques against the live lab, correlates resulting alerts by MITRE ATT&CK technique,
host and timing, then classifies validation outcomes as Detected, Delayed or Missed.
- Automatic multi-stage attack-chain correlation into incidents
- Threat-hunting query language with saved hunt workflows
- Analyst-approved SOAR actions with hard safety guardrails
- MITRE ATT&CK tagging, heatmap, timeline and risk context
- IOC watchlists, case evidence, assignment and resolution tracking
- Standalone Windows executable build plus hosted deployment mode
- Security hardening including a real stored-XSS finding and fix
- Dependency scanning, security headers, login lockout and RBAC
Validation finding: Sentinel BAS exposed pipeline defects that normal rule review did not reveal,
including missing TicketEncryptionType extraction that made the Kerberoasting rule structurally unable to fire,
plus forwarder self-noise that polluted telemetry.
Local AI · Security Engineering
ARGUS
Autonomous Reconnaissance and Guardian Unified System. A fully local Windows AI/voice assistant using FastAPI, Ollama, faster-whisper, Piper TTS, a custom HUD and real hardware telemetry.
A dedicated security audit identified and fixed eight vulnerabilities including XSS-to-RCE, unauthenticated local API access, SSRF and credential disclosure.
Purple Team · Active Directory
Active Directory Security Lab
An enterprise-style AD lab for end-to-end attack-and-detection workflows including LLMNR poisoning, Kerberoasting, AS-REP Roasting, credential abuse, lateral movement, DCSync and Golden Ticket scenarios.
Linux · Operating Systems
SODIK OS
A custom bootable Arch Linux-based operating-system project built as a functional environment with system customization, security tooling and a distinct cyber-oriented interface.
Web · Education · AI
Polszczyzna & IELTS Platforms
Polszczyzna is a Polish-learning platform for Uzbek-speaking beginners. I also built four personalized IELTS-preparation apps using Next.js 14, Tailwind CSS, Supabase, Vercel and AI integrations.