Build
Projects
Tools operators can use, writing that clarifies the craft, and the systems I test ideas in.
Most of this ships through Scott’s Lab. Each entry below says what the project is for and what it produced. The sidebar jumps to a section here or opens the live tool, the write-up, or the repo.
SOAR lab: a human gate between the SIEM and the firewall Link to heading
Wazuh was already blocking flood sources on the pfSense WAN, with no context: a scanner and a large CDN got the same 24 hour block, and one night it blocked Google, Meta and my own media server. This build puts a SOAR layer in front of that action. The Wazuh alert posts to a Shuffle webhook, the playbook enriches the source (RDAP, Tor exits, Spamhaus DROP, the lab’s own 40,000 entry IOC list, AbuseIPDB and VirusTotal when keys are present), applies an allowlist and an out-of-state check before any scoring, and posts a verdict back into Wazuh as an event. Three rules turn that verdict into block, close or escalate, and only the block rule reaches the existing pfSense response. Escalations land in DFIR-IRIS with the evidence attached and carry a one-click, token-gated approve link served by n8n, plus a push to my phone. Every outcome, automatic or approved, is a case.
Stack: Wazuh · Shuffle · n8n · DFIR-IRIS · pfSense · Next.js for the project page
Outcome: Three verdict paths tested end to end, under a second from alert to the block table, and a 12 hour report that counts the right things: 24 firewall blocks, 16 SOAR verdicts, 8 escalations on the first run
See it: project page with the 86 second walkthrough, the write-up, the code, scrubbed and MIT
In-house hosting for the lab Link to heading
The SOAR project page, and the lab’s status dashboard behind it, run on my own hardware: a small Debian container on Proxmox, one systemd template unit per Next.js app, a deploy that is git pull, build and restart, and a Cloudflare tunnel with an Access policy in front of anything that is not meant to be public. No Vercel, no exposed ports. A new app scaffolds from a script in about thirty seconds and is on GitHub from its first commit.
Stack: Proxmox LXC · Debian · Node via mise · systemd · Cloudflare Tunnel and Access · Next.js + shadcn
Use when: You want a portfolio piece or an internal tool live on your own infrastructure with identity in front of it, and you want the next one to take minutes
Vulnerability reporting framework Link to heading
Internal Python framework built at the City of Carmel. It ingested vulnerability exports across 40+ network segments, mapped findings to MITRE ATT&CK, and produced dual-format reports, cutting monthly analysis from hours to under 30 seconds.
Stack: Python · MITRE ATT&CK · reporting pipelines
Outcome: Faster triage, clearer leadership briefs, less spreadsheet archaeology
AI agent & MCP automation Link to heading
Hands-on work running AI coding agents and MCP-integrated automation platforms: scheduled agent jobs, sandboxed execution, and credential-scoped workflows. The SOAR lab above was built this way, across a fleet of agent sessions on the lab’s own machines. The practical write-up lives in the Lab post on hacking with AI.