NYX
publicSIEM correlation engine with automated SOAR response — stateful multi-source log analysis, YAML detection rules, YARA integration, Grafana dashboard.
Security Engineering / SOC & Pentest Track
Computer engineering student at École Polytechnique de Lomé, specializing in cybersecurity. I work across the full loop — hardening systems, simulating attacks against them, and increasingly, building the detection layer that catches the attack in the act.
$ whoami
name Adrien Kpodonou role SOC / Pentest track focus detection engineering, network security status open to opportunities
01
I'm Adrien Kpodonou (KPODONOU Kossigan Gaël God-Love), a computer engineering student aiming for SOC Analyst and pentesting roles. My background is split between offense and defense: I've hardened Samba file servers against real attack tooling (Hydra, CrackMapExec), executed and defended against Layer 2 attacks (ARP spoofing, MITM), and I'm currently building toward detection engineering — SIEM correlation, alerting, and automated response, not just "the attack worked."
I run everything on a Fedora / QEMU-KVM home lab, work comfortably in Linux and Python, and I'm active in CTF competitions (crypto, forensics, steganography). I write up what I build — most of it lives on GitHub with full evidence, not just a description.
02
03
SIEM correlation engine with automated SOAR response — stateful multi-source log analysis, YAML detection rules, YARA integration, Grafana dashboard.
Terraform/Ansible-deployed hardened web stack: ModSecurity WAF (846 OWASP CRS rules) in front of Juice Shop, Grafana/Loki SOC monitoring, full recon→exploit kill-chain with 12 documented root-cause fixes.
Hardened Samba SMB2/3 file server for a simulated SME: per-department access control, Fail2ban, encrypted transport, automated backup/restore, and a Flask admin portal over it. Tested against Hydra, CrackMapExec, and anonymous enumeration.
ARP spoofing MITM executed end-to-end with SSH traffic interception, a validated static-ARP countermeasure, and an honestly-documented MAC flooding attempt against virtualization limits.
3-VM KVM/libvirt SOC environment: Windows AD + client + Fedora SIEM. Simulated intrusion chain (LOLBin → persistence → Kerberoasting) mapped to MITRE ATT&CK, detected via custom Wazuh rules, with SOAR-driven OSINT enrichment.
Java desktop app managing VirtualBox lab environments for security analysts — groups VMs by lab, drives them via VBoxManage, timestamps analyst notes, exports PDF incident reports. Strategy-pattern design for multi-hypervisor support.
04
05