Deploying OpenCTI for Threat Intelligence
Provisioned a production-ready OpenCTI stack on AWS EC2 with Docker Compose, and wired in live AlienVault OTX feeds so indicators (IPs, hashes, domains) flow into the dashboard in real time.
Cyblack Internship — 6 Sprint Report. Threat intel, cloud, governance, awareness, offense, and defense, in one trail.
Six posts, one thread: each sprint below was logged individually on LinkedIn as it happened. This page pulls them into a single record. Tap through to any entry for the full write-up.
Provisioned a production-ready OpenCTI stack on AWS EC2 with Docker Compose, and wired in live AlienVault OTX feeds so indicators (IPs, hashes, domains) flow into the dashboard in real time.
Led Team 6 in moving Maclosec from a vulnerable posture to Zero-Trust on Azure — RBAC and Azure Firewall, service endpoints for data sovereignty, Managed Identities on AKS, and Sentinel-driven SOAR playbooks.
Authored the Information Security Policy and its Zero Trust mandate as lead author, helped integrate SAST/SCA scanning into the SSDLC, and consolidated the team's work into a 14-page report and board presentation.
Reframed people as the strongest defensive layer rather than the weakest link — analyzed a real logic-error incident, built a football-themed awareness reel on canary deployments, and audited tooling for accessibility with axe DevTools and PAVE PDF.
Operated as penetration tester on a healthcare portal audit — mapped hidden endpoints with Nmap and Gobuster, escalated privileges via a broken JWT signature check, ran prompt-injection tests against an integrated AI agent, and reached root through a misconfigured upload feature.
Analyzed WannaCry and Tasker/Molotov malware variants, authored 5 NIST-aligned incident response playbooks, built custom KQL detections in Microsoft Sentinel for impossible travel and C2 beaconing, and planned remediation across a 500-device mobile fleet.