Home About Projects Skills Journey Blog Contact
Building from Africa · Eyes on the global stage
Home/Projects
01 Field Work

Things I built to break things

Twelve tools across offense, defense, and cloud. Every card opens a case study with the real output — not a description of what it should do.

01

Offensive Tools

Attack. Probe. Break. — Recon automation, network analysis, wireless auditing, exploitation tooling.

CompletePython · CLI

r3con — OSINT Recon Tool

Multi-phase recon pipeline: passive subdomain enumeration, HTTP probing, rule-based tech fingerprinting, banner grabbing, Shodan enrichment, dual JSON+TXT reports with risk flags.

PythonShodan APIdnspythonRichWHOIS
Problem
Manual recon across multiple tools is slow and inconsistent. Fragmented results across 5 terminal windows with no unified report or risk scoring.
Attack Scenario
An attacker finds forgotten subdomains via crt.sh, probes alive hosts, fingerprints Apache + WordPress versions, grabs an SSH banner revealing an outdated OpenSSH build, then checks Shodan for known CVEs — all in minutes.
Real Output
└─$ python r3con.py -d scanme.nmap.org
[+] Found 1 subdomain | IP: 45.33.32.156
[+] ALIVE scanme.nmap.org [200] (0.93s)
[+] Tech: Apache/2.4.7 (Ubuntu)
[+] Port 22 open [SSH] SSH-2.0-OpenSSH_6.6.1p1
[!] No HTTPS detected — traffic in plaintext
Impact
⚡ Reduces recon time 80%⚡ Surfaces hidden subdomains⚡ CVE correlation
CompletePython · Scapy

NetWatch — Network IDS

Real-time network intrusion detection built on Scapy. Detects ARP spoofing, port scans, SYN floods, and DNS anomalies. Flags MITM attempts and reconstructs TCP streams.

PythonScapyTCP/IPIDS
Problem
ARP poisoning and port scans often go undetected because most defenders don't have scripted detection running on their local networks.
Detection Output
[*] Capturing on eth0...
[!] ARP SPOOF DETECTED
  MAC 08:00:27:aa:bb:cc claims 192.168.1.1
  Previously: 08:00:27:11:22:33
[!] MITM RISK — two MACs for same IP
Impact
⚡ Real-time ARP detection⚡ SYN flood detection⚡ No GUI required
CompletePython · Flask

VulnLab — Vulnerable Web App

Custom DVWA-style target with documented SQLi, XSS, IDOR, SSRF, and command injection — each with a full attack walkthrough and the actual fix applied.

PythonFlaskOWASP Top 10SQLite
Attack + Fix
# VULNERABLE
query = f"SELECT * FROM users WHERE user='{username}'"
# Input: admin' -- → auth bypass

# FIXED
query = "SELECT * FROM users WHERE user=?"
cursor.execute(query, (username,))
Impact
⚡ 10+ vulnerability classes⚡ Attack + fix per vuln
CompletePython · Scapy

Wireless Auditor

WiFi security auditing tool. Scans for open networks, detects WEP/WPA misconfigurations, captures handshakes, and identifies rogue APs on the local radio environment.

PythonScapy802.11WPARF
Problem
Most wireless auditing requires expensive tools or complex setups. This runs on any Linux box with a wireless adapter in monitor mode.
Scan Output
[*] Scanning on wlan0mon...
[!] OPEN network: "CafeGuest" — no encryption
[!] WEP network: "OldRouter_5G" — crackable
[+] Rogue AP detected: BSSID spoofing "HomeNetwork"
[+] WPA2 handshake captured — 3 targets
Impact
⚡ Detects rogue APs⚡ Flags weak encryption⚡ Zero external deps
02

Defensive & Forensics

Detect. Hunt. Respond. — Log analysis, endpoint detection, incident response, and what attackers leave behind.

CompletePython · PowerShell

Windows Event Log Analyzer

Parses Windows Security, System, and PowerShell logs to flag lateral movement, privilege escalation, and persistence mechanisms.

PythonPowerShellDFIREVTX
Detection Output
[*] Parsing Security.evtx... 48,291 events
[!] Event 4625 x47 in 2min — BRUTE FORCE
[!] Event 4688: cmd.exe → mimikatz.exe
[!] Event 4624 NTLM: WORKSTATION → DC01
[+] 3 high-severity alerts flagged
Impact
⚡ Surfaces brute force⚡ Detects mimikatz⚡ Maps lateral movement
CompletePython · LDAP

AD Auditor

Active Directory security auditor. Enumerates users, groups, GPOs, and ACLs to surface privilege escalation paths, stale accounts, and misconfigured permissions.

PythonLDAPActive DirectoryRBAC
Problem
AD misconfigurations are the #1 vector in enterprise breaches. Most orgs don't audit them until after the incident.
Audit Output
[*] Enumerating CORP.LOCAL...
[!] 3 users with AdminSDHolder — shadow admins
[!] 12 stale accounts (90+ days, still enabled)
[!] GPO "DefaultDomainPolicy" — weak password policy
[+] Kerberoastable accounts: 4 found
Impact
⚡ Finds shadow admins⚡ Kerberoast detection⚡ GPO auditing
CompletePython · DFIR

Forensics Toolkit

DFIR artifact collection and triage toolkit. Extracts prefetch files, registry hives, browser history, recently accessed files, and USB artifacts from Windows endpoints.

PythonVolatilityRegistryPrefetch
Triage Output
[*] Collecting artifacts from C:\...
[+] Prefetch: 47 entries — mimikatz.exe found
[!] Registry: AutoRun key modified 2026-05-01
[!] USB: Unknown device mounted 3x this week
[+] Timeline exported — 112 IOCs flagged
Impact
⚡ Full artifact triage⚡ Timeline reconstruction⚡ USB forensics
CompletePython · IR

IR Framework

Structured incident response automation. Guides through identification, containment, eradication, and recovery phases with automated evidence collection and report generation.

PythonNIST IRAutomationReporting
IR Workflow
[IDENTIFY] Incident type: ransomware
[CONTAIN] Network isolation script — executed
[ERADICATE] IOC sweep — 3 hosts flagged
[RECOVER] Backup integrity verified
[+] IR report generated — PDF + JSON
Impact
⚡ NIST IR aligned⚡ Automated evidence chain⚡ PDF reporting
03

Cloud & Infrastructure

Misconfigure. Detect. Harden. — Cloud misconfiguration scanning, honeypots, threat intel automation.

CompletePython · AWS

AWScan — AWS Misconfig Scanner

Automated detection of IAM privilege escalation paths, public S3 buckets, open security groups, missing CloudTrail logging, and VPC misconfigurations.

PythonBoto3AWSIAMCLI
Scanner Output
[*] Scanning AWS account: 123456789012
[CRITICAL] S3 'company-backups-prod' is PUBLIC
  Objects: 847 | Size: 2.3GB
[HIGH] IAM Role 'dev-role' has iam:* permissions
[HIGH] SG sg-0abc123 port 22 open to 0.0.0.0/0
[INFO] 3 critical findings. Report saved.
Impact
⚡ Finds public S3 buckets⚡ Maps IAM escalation⚡ Flags exposed ports
CompletePython · n8n

Honeypot + Threat Intel Reporter

Deployable honeypot capturing attacker TTPs. Fake SSH and HTTP listeners log every interaction, enrich IPs via AbuseIPDB, and auto-generate reports via n8n.

PythonLinuxn8nAbuseIPDB
Live Output
[*] Honeypot active on ports 22, 80, 443
[HIT] 185.220.101.45 SSH login attempt
[!] AbuseIPDB: 97% — Tor exit node
[n8n] Report → Slack notification sent
[+] 24h: 847 attempts, 23 unique IPs
Impact
⚡ Passive attacker intel⚡ TTP capture⚡ Automated reporting
CompletePython · n8n

Threat Intel Platform

Automated threat intelligence lifecycle. Ingests IOCs from multiple feeds, correlates against local logs, deduplicates, scores by severity, and pushes alerts via n8n workflows.

Pythonn8nSTIXAbuseIPDBIOC
Pipeline Output
[*] Ingesting 3 feeds — 1,247 IOCs
[+] Deduped to 834 unique indicators
[!] 12 IOCs matched local firewall logs
[!] 185.220.101.45 — Tor exit, score: 97%
[n8n] Slack alert + report dispatched
Impact
⚡ Multi-feed ingestion⚡ Local log correlation⚡ Automated alerting
CompletePython · Docker

Container Scanner

Docker and Kubernetes security scanner. Audits container configs for privileged mode, exposed sockets, missing resource limits, and K8s RBAC misconfigurations.

PythonDockerKubernetesRBACYAML
Scan Output
[*] Scanning 8 containers + 12 K8s manifests
[CRITICAL] nginx:latest — running as root
[HIGH] Docker socket mounted in app container
[HIGH] K8s ClusterRoleBinding to cluster-admin
[INFO] 5 critical findings. Report saved.
Impact
⚡ Docker + K8s coverage⚡ RBAC misconfiguration⚡ Container escape risks

Want this kind of tooling on your side?

I take on freelance security work, custom tooling, and lab builds. Tell me what you're defending.