Tools & Stack
Current security and workflow toolkit.
infra_cloud
- → GCPCompute Engine / IAM / KMS / Kubernetes Engine and Cloud SQL
- → CloudflareDNS / Edge Computing (Workers) / Reverse Proxy
- → TerraformIaC / Modules for tool deployment / Automation
- → AnsibleConfig Management / Task Orchestration
- → GitLabGit server / CI/CD Automation / Build agent
- → PostgreSQLSelfhosted DB / In-cluster DB / Managed DB
security_stack
- → TenableVulnerability Scanning / Exposure Management / ASV
- → CloudflareWAF / API Shield / DDoS Protection / TLS
- → BlackDuckSAST / Software Composition Analysis / SBOM
- → SentinelOneEDR / XDR / Incident Respone / STAR Automation
- → AzureIdentity Provider / SSO / Joiner-Mover-Leaver Automation / Exchange Server
- → IntuneMobile Device Management
- → KandjiMacOS Centralized Management
- → SumoLogicCentralized Logging / SIEM / Monitoring and Alerting / Incident Response and Investigation
- → NewRelicDistributed Tracing, Incident Response, APM
- → FortiGateVPN Server and Client
- → IPQSIP address data enrichment
- → WhoISXMLReverseIP Lookups / ReverseDNS Lookups / Investigations
- → MaltegoAttack Surface Mapping / OSINT
- → SnykSAST / SCA
- → WazuhHost-based IDS/IPS
- → KnowBe4Phishing Simulation / Security Awareness Training
- → OWASP Threat DragonThreat Modeling
workflow
- → ObsidianWhat you use it for / approach / key insight
- → PostmanAPI testing / Documentation
- → VSCodiumIDE
- → CursorAI IDE
- → ExcelLove/Hate relationship
utilities
- → gcloudWorking with GCP / Scripting
- → nmapEnumeration / Scripting
- → amassAttack Surface Mapping
- → sshSSH-ing into things