AWS Security Lab Series

Hands-on labs built for security practitioners learning cloud security. Each lab follows a five-phase format: Setup → Attack → Detect → Remediate → Cleanup.

Terraform handles deployment. CLI handles hardening. Everything is reproducible.


Detection Engineering

SIEM detections mapped to MITRE ATT&CK, built and tested in production environments. Runbooks documented in Notion.


CTF & Lab Work

Active Directory attack chains (RBCD, ADCS/ESC1, Kerberoasting, GPO abuse), Linux privilege escalation, network pivoting.