Skip to content
View LiamCarPer's full-sized avatar

Highlights

  • Pro

Block or report LiamCarPer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
LiamCarPer/README.md

Liam Carvajal

OT Detection Engineer | Detection-as-Code · OT NDR · MITRE ATT&CK for ICS

I build OT detection that holds up in a real plant. That means content written once and generated everywhere, rules that understand what a Modbus function code or a DNP3 operate actually does, and coverage measured against adversary emulation instead of guessed at. Architecture is part of that job too — zones and conduits, IT/OT segmentation and DMZ design, secure remote access — because a detection is only ever as good as the telemetry the network lets through. I work across legacy industrial protocols (Modbus, PROFINET, DNP3, OPC UA, IEC 61850) and the brownfield reality of adding monitoring to a running facility.

Currently OT Security Analyst (Incident Response & Threat Hunting) @ Rockwell Automation — industrial detection, threat hunting and incident response in production OT environments.

LinkedIn · Email · Spain · Open to EU remote & B2B / contract engagements


🔍 How detection reaches the plant

The rule source is the center of gravity. Everything downstream — edge sensors, SIEM queries, coverage metrics — is generated from it, so nothing drifts and no rule is deployed by hand.

graph TD
    subgraph "Detection as Code"
        DE[OT Detection Engineering<br/>Sigma rules · protocol decoders · native Suricata]
    end

    subgraph "Plant / Edge (OT-Security-Lab)"
        PLC[PLCs · HMIs] -->|Modbus · DNP3 · S7comm · OPC UA| GW[Edge DPI / OT Gateway]
        GW -->|Suricata · Zeek| ML[Malcolm NDR Pipeline]
    end

    DE -.->|Sigma to Suricata| GW
    DE -.->|Sigma to Loki / OpenSearch| ML
    ML -->|Fluent Bit| S3[S3 Raw Telemetry]
    S3 -->|SQS · Lambda| LP[Log Parser Toolkit]
    LP -->|Detections| DDB[(DynamoDB)]
    DDB -->|Streams| IR[Automated NIST Reports]

    style DE fill:#cfe2ff,stroke:#333
    style GW fill:#f96,stroke:#333
    style LP fill:#ff9,stroke:#333
    style IR fill:#dfd,stroke:#333
Loading

🛡️ Detection Engineering at a Glance

  • Rules as software — pySigma-based validation over a parsed rule model, positive/negative fixtures, and structural governance for native Suricata rules.
  • Protocol-aware content — application-layer detections for Modbus, DNP3, S7comm and OPC UA, backed by Rust decoders rather than fragile byte offsets.
  • Coverage you can prove — ATT&CK for ICS coverage and MTTD / false-positive metrics derived from the rules themselves, never hand-maintained.
  • Proven, not assumed — content exercised against adversary emulation and a live lab run before it is trusted.
  • One rule, many consumers — Splunk, Microsoft Sentinel, OpenSearch and Grafana Loki queries all generated from a single source of truth.

🎯 Featured Work

The Problem: OT detection content is written once, deployed by hand, duplicated across the SIEM and the NDR, and never measured — so nobody can say which ATT&CK for ICS techniques are covered, how fast detections fire, or whether a rule change broke one. The Solution: A detection-as-code pipeline that treats detections as software: OT Sigma rules and native protocol DPI (Modbus, DNP3, S7comm, OPC UA), with Rust DNP3, S7comm and OPC UA decoders for application-layer events, validated and converted in CI from a single source of truth, proven against adversary emulation and deployed into a Malcolm NDR pipeline and the OT-Security-Lab Loki stack.

  • Detection Engineering: Built a pySigma-based validation matcher over the parsed rule model, labeled positive/negative fixtures, and structural governance for native Suricata rules. ATT&CK for ICS coverage and MTTD/false-positive metrics are generated, never hand-maintained.
  • Impact: Verified against a live run of OT-Security-Lab — 4/4 emulation expectations detected at a 2.45 s mean MTTD, with Loki, OpenSearch, Splunk and Microsoft Sentinel queries generated from one rule source.
  • Stack: pySigma/sigma-cli, Sigma, Suricata, Rust, Grafana Loki, OpenSearch, Splunk, Microsoft Sentinel, JSON Schema, Python, GitHub Actions.

The Problem: Commercial NDR (Nozomi/Claroty) is cost-prohibitive for many facilities. The Solution: A production-grade NDR pipeline using CISA Malcolm, Arkime, and Suricata, enriched by a custom Python SOAR layer.

  • Impact: Implemented automated DPI profiling of Modbus function codes to identify unauthorized register manipulation before it hits the SIEM.
  • Stack: CISA Malcolm, Arkime, Suricata, Python (Scapy/Tshark).

The Problem: SOC analysts in OT environments drown in high-noise alerts. Generating NIST-aligned incident reports and Suricata rules manually is slow, inconsistent, and doesn't scale. The Solution: An agentic AI pipeline that detects anomalies via Isolation Forest, enriches them with RAG-augmented OT knowledge (IEC 62443, asset inventories, past incidents), and produces NIST SP 800-61 reports with custom Suricata rules — all without human intervention.

  • Engineering Challenge: Built a deterministic classification layer that routes alerts to the correct analysis path before LLM invocation, eliminating token waste. Made the agent LLM-agnostic — swap between GPT-4o-mini and local Ollama models by changing two env vars.
  • Stack: Python, LangChain/LangGraph, ChromaDB, FastAPI, scikit-learn, OpenAI/OpenRouter, Pytest. 25 deterministic tests pass in CI without API keys.

OT-Security-Labthe environment my detections are validated against

The Problem: You can't test attacks on live water treatment plants. The Solution: A 5-zone Docker-based simulation of a water filtration facility mapped to the Purdue Model and IEC 62443, with every inter-zone conduit enforced through a dedicated iptables gateway.

  • Architecture Judgment: Isolated the Historian in Level 3 to enforce unidirectional data flow, fulfilling IEC 62443 requirements for zone-to-zone restricted access.
  • GRC Depth: Full IEC 62443 gap analysis, threat model mapped to MITRE ATT&CK for ICS (T0800–T0890), asset inventory, risk register & BIA (12 scenarios), IR playbook, and STIG-style hardening guides.
  • Stack: OpenPLC, Scada-LTS, Iptables (Zone Firewall), InfluxDB, Grafana, Docker Compose.

The Problem: Ingesting OT telemetry into AWS is often rigid and expensive while respecting segmentation boundaries. The Solution: A serverless, event-driven pipeline that ingests, parses, and archives OT security events in real-time.

  • Engineering Challenge: Solved LocalStack Community constraints by implementing a Fat-Zip dependency injection at cold-start and a dynamic gzip detection layer for Fluent Bit payloads.
  • Stack: Terraform, AWS Lambda, DynamoDB, S3, Snappy/Parquet, Fluent Bit.

The Problem: SIEM ingestion is only as good as its parser. The Solution: A memory-efficient, stateful parsing engine for unstructured logs.

  • Technical Nuance: Uses the Generator pattern to process multi-gigabyte logs with near-zero RAM overhead. Features a stateful middleware for correlating SSH brute force and web scanning across time windows.

🧰 Systems, Coding & Applied AI

The detection work only holds if the tooling underneath it does. Alongside the OT projects I write memory-safe parsers, analyzers and ML tooling.

  • Rust Security Toolkit — Rust CLI for Solana transaction forensics, IDL-aligned account validation and instruction simulation. 56 integration tests.
  • Solana Audit Toolkit — syn-based static analyzer for missing signer checks, missing owner constraints, discriminator collisions and CPI privilege escalation, plus a ProgramTest fuzzer. 40 tests, 3 shipped audit findings.
  • AetherPdM — Predictive maintenance for rotating equipment: vibration DSP (FFT, envelope), PyTorch autoencoder anomaly detection that beat the sklearn baseline on real CWRU validation, MQTT streaming ingestion, and ONNX edge deployment.
  • GatedOps — Reference MLOps platform: gated train/evaluate/promote/serve with byte-exact lineage and serving-quality gates.
  • Open source: CISA Malcolm (OT/ICS protocol visibility for Modbus TCP in the DPI pipeline), socketioxide (volatile events, remote-adapter core refactor), sqlx (SQLite datetime builder off a deprecated API).

🧠 Technical Arsenal

Detection, Network & Response Sigma pySigma Suricata Zeek Malcolm NDR Arkime Wireshark Scapy Splunk Microsoft Sentinel OpenSearch Grafana Loki MITRE ATT&CK for ICS

OT / ICS Security IEC 62443 Purdue Model NIS2 BDEW Modbus/TCP PROFINET DNP3 OPC UA IEC 61850 S7comm

Cloud & Infrastructure AWS Lambda Terraform Docker Kubernetes

Rust, Python & Systems Rust Python Linux iptables SQL

Applied ML & Data PyTorch scikit-learn MLflow Parquet MQTT


📈 Professional Development

  • Certification path: ISA/IEC 62443 Cybersecurity Fundamentals Specialist (IC32) → GICSP.
  • Focus: detection engineering at scale, ATT&CK for ICS coverage and adversary emulation (TRITON/Industroyer), OT network segmentation and secure remote access, and NIS2 / CRA compliance.

🤝 Let's Collaborate

My full-time focus is defending OT/ICS environments; on the side I keep building open tooling at the intersection of OT detection and applied AI. I'm open to connecting on detection research, joint adversary-emulation work, open-source collaboration and technical advisory for industrial detection challenges — as well as EU-remote and B2B / contract engagements.

LinkedIn · Email

Popular repositories Loading

  1. log-parser-toolkit log-parser-toolkit Public

    Python

  2. OT-Security-Lab OT-Security-Lab Public

    Simulated OT/ICS security lab for a water treatment facility: Purdue Model segmentation, protocol-aware detection (Modbus/DNP3), physics-aware safety monitoring, Grafana/Loki SIEM, policy-as-code, …

    Python

  3. OT-NDR-Malcolm-Pipeline OT-NDR-Malcolm-Pipeline Public

    Python

  4. cloud-telemetry-lake cloud-telemetry-lake Public

    Python

  5. LiamCarPer LiamCarPer Public

    OT Detection Engineer

  6. ics-agentic-soc-pipeline ics-agentic-soc-pipeline Public

    Jupyter Notebook