Skip to content
View scott-renny's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report scott-renny

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
scott-renny/README.md

Scott Renny

Security+ Certified · AWS Certified AI Practitioner · Cybersecurity Engineering · Security Operations

I build, secure, monitor, recover, and document real infrastructure in a continuously evolving home Cyber Operations Center.

CompTIA Security+ AWS Certified AI Practitioner COC Phase 10 in progress Current milestone Active Directory identity lab LinkedIn


About me

I hold CompTIA Security+ and AWS Certified AI Practitioner certifications. My near-term target is an entry-level cybersecurity/SOC-oriented role, and I'm deliberately building broader capability in security engineering, cloud and cloud security engineering, and AI-assisted automation engineering through hands-on, production-style projects.

My portfolio goes beyond installing tools. Each major project documents the architecture, security decisions, implementation, validation evidence, failure modes, recovery procedures, and lessons learned behind the finished system.

My working method is simple:

Plan → Build → Secure → Validate → Monitor → Recover → Document → Improve

Portfolio snapshot

Area Current evidence
Cloud engineering Cognito-approved serverless ticket intake, scoped workload permissions, DynamoDB persistence, SNS email, EC2 IMDSv2 and teardown validation
Security operations Wazuh endpoint monitoring, alert analysis, Sysmon telemetry, MITRE ATT&CK context, malware remediation
Identity security Windows Server 2025 AD DS/DNS, OU/group design, AGDLP-style privilege assignment, separate daily/admin/Tier-0 identities, Protected Users, gMSA and Kerberos attack-path practice
Infrastructure security Hardened Ubuntu Server, Windows endpoint baselines, Docker segmentation, private HTTPS administration
Network security Tailscale/private access, Pi-hole DNS policy, UFW, device discovery, network metadata, access-control design
Observability Zeek, Prometheus, Grafana, Graylog, centralized Windows and Linux telemetry
Recovery engineering Automated rsync and Restic backups, encrypted retention, integrity checks, representative restore validation
Automation Python, PowerShell, Bash, systemd, scheduled jobs, REST APIs, GitHub workflows
AI-assisted automation Deterministic eligibility/safety gates, grounded document generation from verified data, reviewer critique, human authority at consequential actions
Engineering governance ADRs, risk registers, change control, evidence handling, validation gates, completion records

Flagship program

A structured 26-phase program documenting the design and operation of an enterprise-inspired Cyber Operations Center.

Completed phases 0–9 (Phase 8.5 remains blocked separately):

  • program governance, risk management, and documentation standards;
  • clean-slate Ubuntu Server foundation and base hardening;
  • Docker platform security and private management access;
  • private remote access, Pi-hole, Wazuh, ClamAV, and scoped firewall controls;
  • encrypted, monitored, and restore-tested backup infrastructure;
  • NET-WATCH network visibility and profile-based DNS enforcement;
  • Zeek, Prometheus, Grafana, and Graylog telemetry;
  • Windows, laptop, phone, and tablet endpoint engineering; and
  • private Nextcloud file access and sync with tested recovery and security controls.

Phase 10 — Identity Services: IN PROGRESS.

The current pre-attack baseline uses Windows Server 2025 on DC01 and a Windows 11 Enterprise domain client in the isolated corp.lab.test lab. AD DS/DNS, protected OU/group design, AGDLP-based workstation administration, separate everyday/admin/Tier-0 identities, Tier-0 workstation logon restrictions, hardened password/lockout policy, a working gMSA/KDS foundation, advanced audit policy, and a deliberately isolated legacy service identity are implemented and validated. I also hardened the default machine-account quota from 10 to 0 with explicit workstation-admin delegation and remediated a multihomed-DC DNS registration issue before capturing clean pre-attack snapshots.

Next work is the isolated Kali attacker and Wazuh/Sysmon telemetry validation, followed by controlled password-spray, Kerberoasting and credential-access exercises, investigation/remediation, incident-response records, and Greenbone/OpenVAS vulnerability-management practice.

Phase 8.5 — Linux Mint Cinnamon Migration remains blocked in parallel pending the Cerberus hardware build; it does not gate independent Phase 10 work.

Project Cerberus delivers this workstation as the Linux Mint Cinnamon engineering platform and primary COC control node.

The next workstation will be built from verified Linux Mint Cinnamon installation media with Secure Boot, full-disk encryption, AppArmor, UFW, selective restoration, Wazuh monitoring, application acceptance testing, and a validated Linux Mint backup before the legacy Windows system is retired.


AI Job Search Automation Platform

One of my strongest individual production-style engineering projects: a production-style AI automation platform with deterministic eligibility and safety gates, grounded document generation from verified candidate information, an independent reviewer-critique pass, controlled browser automation, and human authority preserved at every consequential decision point. It is not presented as fully autonomous — a CAPTCHA, security question, or ambiguous requirement always hands control back to a human.

Operational private platform · public portfolio showcase published.

View the public showcase →


Featured repositories

These repositories are the curated entry points to my current portfolio.

Repository What it demonstrates Core technologies
Cyber Operations Center Engineering Program Phased security-operations program spanning infrastructure, endpoints, telemetry, recovery, identity and governance Wazuh · Active Directory · Zeek · Docker · Linux · Windows
AI Job Search Automation Platform Production-style AI automation with deterministic safety gates, grounded generation, reviewer critique, and human-controlled submission Python · Claude/Groq · Playwright · systemd
NET-WATCH Complete, operational, maintained network visibility and profile-based DNS access-control platform Python · Flask · Pi-hole · Nmap · Wazuh
Project Hermes Stable v1.0.1 release — repeatable Windows provisioning, validation, backup, restoration, and maintenance, validated by 381 automated tests PowerShell · Pester · Windows Security
Cloud Engineering Portfolio Completed AWS starter series and Family IT Help Desk v0.2 authenticated ticket management AWS · Cognito · Lambda · DynamoDB · SNS
Project Cerberus Linux Mint Cinnamon engineering workstation and primary COC control-node build Linux Mint · Cinnamon · AppArmor · UFW
Project Daedalus Self-hosted automation and intelligence workflows with explicit governance n8n · APIs · JSON · Automation
Security+ Trainer Browser-based study tools, exercises, and mock examinations HTML · CSS · JavaScript · Security+

Additional engineering work

Project Focus
Project Ares Isolated adversary simulation and detection validation — design & planning stage
Project Apollo Samsung mobile-device security hardening and validation
Project Atlas Operational Ubuntu infrastructure; completed hardware restoration, unattended power/reboot recovery, and owner-confirmed external SSH/remote-development acceptance
Pi-hole DNS Infrastructure DNS filtering, policy enforcement, and resilient name resolution
Home Lab Network Security Network architecture, segmentation, secure administration, and defensive controls
HomeSOC Preserved SOC-oriented home-lab engineering
Backup Lab Preserved Linux backup automation and recovery engineering
Legacy Project Archive Earlier work showing the progression of my engineering practices

Technical toolkit

Domain Technologies and practices
Operating systems Ubuntu Server, Windows Server 2025, Windows 10/11, Linux Mint Cinnamon
Security and telemetry Wazuh, Sysmon, Zeek, Suricata, ClamAV, Graylog, MITRE ATT&CK
Identity Active Directory Domain Services, DNS, Group Policy, Kerberos, AGDLP, Protected Users, gMSA
Infrastructure Docker, Docker Compose, Dockge, systemd, Caddy, Samba, virtualization
Networking TCP/IP, DNS, DHCP, Pi-hole, Tailscale, UFW, Nmap, segmentation concepts
Observability Prometheus, Grafana, structured logs, health checks, operational dashboards
Automation and development Python, PowerShell, Bash, Flask, REST APIs, HTML, CSS, JavaScript
Recovery Restic, rsync, retention policies, integrity checks, hash comparison, restore testing
Engineering practice Architecture decisions, risk analysis, change control, evidence handling, runbooks

Atlas v1 completed its September 7, 2026 unattended-operation resilience milestone using the existing laptop battery, BIOS Wake on AC, systemd and Docker restart policies. Optional evidence follow-up does not reopen the completed operational milestone.

Current direction

  • Pursuing entry-level cybersecurity / SOC-oriented roles as my near-term target
  • Deliberately building toward security engineering, cloud/cloud security engineering, and AI engineering & automation through hands-on, production-style projects — direction, not a current title
  • Building COC Phase 10 Identity Services with a validated Windows Server 2025/Windows 11 pre-attack baseline, privilege separation, delegated administration, advanced auditing, and the controlled attack/detection chapter next
  • Operating the completed Phase 9 Nextcloud platform without reopening accepted scope
  • Keeping completed Atlas infrastructure operational through simple, reusable recovery controls
  • Progressing a booked AWS certification path: Cloud Practitioner (Oct 24), Solutions Architect – Associate (Nov 28), Security – Specialty (Dec 19, 2026)
  • Building on the completed AWS starter series and Family IT Help Desk v0.2 authenticated ticket management
  • Expanding detection engineering and threat-hunting skills
  • Developing incident-response and digital-forensics workflows

Professional highlights

  • CompTIA Security+ certified
  • AWS Certified AI Practitioner (AIF-C01), earned August 29, 2026
  • Information Security Analyst Program — Correlation One graduate
  • Graduated with Honors and a 96% final average
  • Building a public, validation-driven cybersecurity engineering portfolio
  • Interested in SOC analysis, infrastructure security, identity security, detection, and incident response

Connect

I welcome conversations with SOC analysts, cybersecurity professionals, infrastructure engineers, recruiters, and people who learn by building.

Connect with me on LinkedIn · Read my engineering journal · Explore all repositories


Build deliberately. Validate continuously. Document everything.

Popular repositories Loading

  1. secplus-trainer secplus-trainer Public

    Interactive CompTIA Security+ study and assessment trainer.

    HTML 2 1

  2. cyber-operations-center-engineering-program cyber-operations-center-engineering-program Public

    Phased Cyber Operations Center engineering program covering networking, SIEM, backup, endpoints, and security operations.

    HTML 2

  3. homesoc homesoc Public

    Legacy cybersecurity engineering project documenting the design and deployment of a self-hosted Security Operations Center using Ubuntu, Docker, Wazuh, CrowdSec, ModSecurity, and Nginx.

    Shell

  4. pihole-dns-infrastructure pihole-dns-infrastructure Public

    Legacy infrastructure engineering project documenting the deployment of a Docker-based Pi-hole DNS sinkhole integrated with Wazuh SIEM, ModSecurity, and Nginx in a multi-service Ubuntu Server envir…

    Shell

  5. backup-lab backup-lab Public

    Legacy infrastructure project documenting Linux backup automation with rsync, Restic, Samba, Cron, and Wazuh.

    Shell

  6. home-lab-network-security home-lab-network-security Public

    Legacy infrastructure engineering project documenting the design and implementation of a software-defined network security architecture using Ubuntu Server, Suricata IDS/IPS, WireGuard VPN, Wazuh S…

    Shell