I build practical security operations capabilities: detection engineering, incident response, threat hunting, intelligence workflows, DFIR tooling, and low-cost security architecture for teams that need security outcomes they can deploy, inspect, and maintain.
| Area | Current Focus |
|---|---|
| π‘οΈ Security Operations | SOC engineering, alert triage, case workflow, response playbooks |
| π― Detection Engineering | Sigma, SIEM/XDR content, MITRE ATT&CK mapping, multi-platform rules |
| π΅οΈ Threat Hunting | IOC/IOA hypothesis building, telemetry pivoting, adversary behavior tracking |
| π§ͺ DFIR | Log analysis, forensic triage, incident reconstruction, investigation tooling |
| π°οΈ Threat Intelligence | IOC enrichment, CVE prioritization, OSINT collection, operational reporting |
| ποΈ Security Architecture | Low-cost security architecture, platform integration, defense capability roadmaps |
| βοΈ Automation | Python, JavaScript, Docker, API integration, SOAR workflow automation |
| βοΈ Cloud Security | AWS/Azure/GCP hardening, Kubernetes, compliance automation, IaC security |
|
Cross-platform security baseline auditing and controlled remediation β Linux, macOS, Windows, FreeBSD, AWS, Azure, GCP, K8s, Docker, Terraform. HTML reports, CIS compliance scoring. |
836 rules, 9 platforms, 152 MITRE ATT&CK techniques. Sigma Β· Elastic Β· Splunk Β· Sentinel Β· Wazuh Β· Carbon Black Β· CrowdStrike Β· SentinelOne Β· Falco. |
Convert YARA rules to Sigma detections and native SIEM/EDR queries. IOC classification, MITRE ATT&CK tagging, CLI, API, Docker Compose. |
|
Centralized threat intelligence & security operations platform. MISP integration, Slack/Teams/Telegram webhooks, IOC registry, STIX export. |
DFIR platform β log & network analyzers, memory triage, Sigma/YARA correlation engine, MFA, Velociraptor integration-ready. |
Threat hunting playbook engine. Repeatable hunts, evidence tracking, ATT&CK Navigator JSON export, analyst-ready Markdown reports. |
|
VAPT Report Dashboard. Import Burp, ZAP, Nmap, Nessus, Nuclei. PDF reports β OWASP, PCI DSS 4.0, NIST CSF, ISO 27001 frameworks. |
Visual Multi-IaC designer β generate Terraform, OpenTofu, Pulumi, or Helm. AI Copilot (DeepSeek/GPT), cost estimator, security scanner. |
DVWA lab with Nginx TLS, multi-arch (x86_64 + ARM). Difficulty toggle, optional Wazuh SIEM agent for security training. |
| Metric | Value |
|---|---|
| π° Public Repositories | 9 |
| π‘οΈ Security Projects | Detection Β· DFIR Β· Intel Β· Hardening Β· Pentest |
| π Detection Rules | 836 rules Β· 9 platforms |
| πΊοΈ MITRE ATT&CK | 152 techniques mapped |
| π All repos | OpenSSF Scorecard Β· Gitleaks Β· Dependabot Β· Pre-commit |
| π Languages | Python Β· TypeScript Β· JavaScript Β· Shell |
My hobby is learning new things. These are security, infrastructure, intelligence, automation, and observability tools I have used or recently studied.
- System Engineer / Cyber Security Architect
- Digital Forensics on Corporate
- Trainer Cyber Security on BUMN
- Automation Engineer
- Head of Cyber Security Team
- Learning new security and infrastructure tooling continuously.
- Designing low-cost IT security architecture that is practical to operate.
- Publishing reusable detection engineering and threat hunting content.
- Improving practical SOC, DFIR, and CTI tooling for small and medium security teams.
- Sharing knowledge for the advancement of Indonesian cybersecurity education.



