$ cat /etc/motd

Cybersecurity

Security is where my systems administration and developer backgrounds converge. All tool details and focus areas are structured clearly below.

## Focus Areas

Networking Fundamentals

TCP/IP, subnetting, and network troubleshooting, sharpened daily resolving enterprise network tickets at Cimas Health Group.

Linux & Hardening

Day-to-day Linux administration across homelab VMs and containers: permissions, services, SSH hygiene, and minimal attack surface principles.

Identity & Access Management

Running Authentik as a centralized identity provider with SSO, OAuth2/OIDC flows, and policy-based access across all self-hosted services.

Governance & Auditing

Building strong foundations in information systems auditing and security protocols through HIT ISACA, backed by hands-on healthcare IT operations.

## Security Tools & Projects

Security tooling, automated vulnerability scanning, and attack surface reconnaissance software.

~/case-studies/help-desk-vault.md

shipped
Cybersecurity Tooling

Cimas Vault — Zero-Knowledge Secret Sharing

Jan 2026 – Aug 2026

An enterprise Zero-Knowledge ephemeral secret-sharing platform designed to eliminate plaintext password and token leakage across help desk operations.

// problem statement
IT technicians and corporate staff frequently share sensitive credentials, database keys, and temporary passwords over unencrypted email, Teams, or WhatsApp messages, creating permanent exposure vectors.
// engineering solution
Architected a zero-knowledge web application using client-side Web Crypto AES-GCM 256-bit encryption. The decryption key is generated in the sender’s browser and stored exclusively in the URL hash fragment (#), ensuring the server never receives the key or plaintext. Built on Upstash Redis with burn-on-view auto-deletion and sliding-window rate limiting.
// key outcome & impact
Guaranteed cryptographic privacy for enterprise IT support operations where even database administrators and hosting servers cannot read transmitted credentials.

System Architecture & Data Flow

Sender Browser (Client-Side Encryption)
  │  1. Generates 256-bit AES-GCM key & IV locally
  │  2. Encrypts secret text ──► Ciphertext payload
  │  3. Assembles link: /view/[id]#[localKey]  (Hash fragment never hits server)
  │
  ├──► POST /api/secret ──► Upstash Redis (Key-Value TTL Store)
  │                          └─ Stores ONLY Ciphertext + Configured Max-Views / TTL
  │
Recipient Browser
  │  1. Retrieves Ciphertext from /view/[id]
  │  2. Extracts #[localKey] from window.location.hash
  │  3. Decrypts secret in-memory ──► Redis atomically burns the key

Key Technical Highlights:

  • True Zero-Knowledge architecture: decryption key is isolated in URL hash fragment and never transmitted over HTTP.
  • AES-GCM 256-bit authenticated client-side encryption with distinct per-secret initialization vectors.
  • Burn-on-view auto-destruction and configurable TTLs (5 min to 7 days) via Redis.
  • Designed and evaluated for enterprise healthcare IT operations during Cimas Health Group tenure.
  • TypeScript
  • Next.js
  • Web Crypto API
  • AES-GCM-256
  • Upstash Redis
  • Tailwind CSS
  • Radix UI

~/case-studies/elic-pdf-tool.md

shipped
Cybersecurity Tooling

Elic PDF Tool — Privacy-First Client-Side Document Suite

Aug 2026

A browser-based document processing suite with Cinema Mode editing, executing all PDF conversions, metadata sanitization, and restructuring 100% client-side via WebAssembly and PDF.js.

// problem statement
Commercial online PDF tools require uploading confidential contracts, medical records, and financial statements to third-party cloud servers, posing severe data leakage and privacy risks.
// engineering solution
Engineered a zero-upload, client-side PDF manipulation application in Next.js and TypeScript. Leverages WebAssembly and pdf-lib to perform document merging, page extraction, stream compression, damaged xref table repair, and metadata sanitization directly within the browser’s memory sandbox without server uploads.
// key outcome & impact
Delivers complete document editing and privacy sanitization without server transmission, ensuring confidential records remain strictly on the user’s local device.

System Architecture & Data Flow

Browser Client Sandbox (Zero Server Upload)
  │
  ├──► PDF.js & WebAssembly Engine
  │      ├─ Memory-isolated document parsing & rendering
  │      └─ Cinema Mode full-screen reading & annotation
  │
  ├──► In-Memory Manipulation Pipeline (pdf-lib)
  │      ├─ Merge, Split, Reorder, Rotate, Crop (N-Up)
  │      └─ Stream compression & damaged xref table repair
  │
  └──► Security & Privacy Layer
         ├─ Metadata Sanitization (strips author, OS, GPS tags)
         └─ Client-side password encryption & permissions lock

Key Technical Highlights:

  • Zero server uploads: 100% of processing, parsing, and rendering occurs inside client browser memory.
  • Automated metadata stripping removing author identity, software signatures, and device metadata.
  • Cinema Mode full-screen distraction-free PDF viewer with zoom, thumbnails, and page rearrangement.
  • Client-side PDF repair, stream compression, and form flattening via WebAssembly.
  • TypeScript
  • Next.js
  • WebAssembly
  • PDF.js
  • pdf-lib
  • Tailwind CSS
  • Data Privacy

~/case-studies/open-channel.md

shipped
Cybersecurity Tooling

OpenChannel — Anonymous Whistleblower & Pulse Platform

Dec 2025 – Present

Multi-tenant whistleblower intelligence and employee feedback platform with zero-knowledge submission anonymity, USSD gateway support, and AI sentiment analysis.

// problem statement
Workplace harassment, fraud, and safety violations go unreported due to employee fear of retaliation, while non-desk and frontline staff in low-connectivity areas lack web portals to speak up.
// engineering solution
Architected a multi-tenant feedback platform using Next.js and Supabase RLS. Strips identifying IP headers and client footprints at the gateway. Built a custom USSD session manager and menu builder enabling frontline staff on basic feature phones to submit anonymous feedback and participate in pulse polls without mobile internet.
// key outcome & impact
Created a secure, untraceable reporting channel with automated NLP sentiment prioritization and dual web + USSD accessibility across corporate and industrial teams.

System Architecture & Data Flow

Reporting Channels:
 Web App (Stripped IP / Headers)         Feature Phone (No Internet)
         │                                       │
         ▼                                       ▼
 Next.js Edge Router                     USSD Session Gateway
         │                                       │
         └───────────────┬───────────────────────┘
                         ▼
             Anonymization Pipeline
         (Strips IP, UserAgent, Metadata)
                         │
        ┌────────────────┴────────────────┐
        ▼                                 ▼
 Supabase Multi-Tenant DB       NLP Sentiment Classifier
 (Isolated Org RLS)             (Toxicity & Priority Triage)

Key Technical Highlights:

  • True anonymous submission pipeline completely decoupling respondent identities and network telemetry.
  • Dual-channel ingestion: responsive web portal alongside USSD gateway for offline frontline workers.
  • Automated NLP sentiment and urgency classification prioritizing critical safety or fraud disclosures.
  • Multi-tenant isolation using Supabase Row-Level Security ensuring organizational data segregation.
  • Next.js
  • TypeScript
  • Supabase
  • PostgreSQL
  • USSD Gateway
  • NLP Sentiment Analysis
  • Tailwind CSS

~/case-studies/vulnerability-assessment-toolkit.md

shipped
Cybersecurity Tooling

Vulnerability Assessment Toolkit

Aug 2026

An automated security auditing shell suite designed for rapid reconnaissance, port scanning analysis, and system attack surface evaluation.

// problem statement
System administrators need fast, repeatable security checks to identify exposed ports, weak permissions, and outdated network services without relying on heavy proprietary scanners.
// engineering solution
Developed a modular Bash and Python auditing suite integrating Nmap scripting engine (NSE), firewall rule audits, and permission scanners with structured markdown and JSON log output.
// key outcome & impact
Automated repetitive port scanning, service versioning, and attack surface enumeration, replacing manual CLI triage with structured JSON and Markdown audit reports.

System Architecture & Data Flow

Target Network / IP ──► Host & Port Recon ──► NSE Vulnerability Audits ──► Structured Report
 (CIDR Input Range)        (Nmap Engine)          (CVE & Service Probes)       (Markdown & JSON)

Key Technical Highlights:

  • Automates multi-phase network reconnaissance and service fingerprinting.
  • Integrates Nmap Scripting Engine (NSE) for common vulnerability and misconfiguration detection.
  • Generates machine-parsable JSON output and clean Markdown audit summaries.
  • Shell
  • Linux
  • Nmap
  • Security Auditing
  • Bash
  • Python

## Interactive Shell

An interactive terminal simulation for quick command-line exploration.

elic@security: interactive shell

Type 'help' to see available commands. Try 'tools' or 'sudo hire me'.

## Credentials & Involvement

  • HIT ISACA Member (2024–Present): Information systems auditing, IT governance, and security protocol fundamentals.
  • Cimas Health Group IT Internship: Hands-on exposure to security-conscious operations in a high-compliance healthcare environment.
  • Homelab Identity Architecture: Authentik SSO deployed in production-style conditions across self-hosted services.
  • Professional Certifications: Actively pursuing ISACA and cloud security credentials.