Hi, I'm Ilian

DevSecOps, SOC, Digital forensics
I build, secure and defend infrastructure. My background is in cloud deployment and DevSecOps automation (AWS, Azure, Kubernetes, CI/CD with security built in) and I specialize in the defensive side: SIEM, malware analysis, honeypots, digital forensics and incident response.

My goal is to grow in SOC, DFIR and security engineering.

About me

Build, secure, defend.

Almost everything I do revolves around those three verbs. My background is in cloud deployment and systems administration, so I first learned to build infrastructure (microservice architectures on AWS and Azure, databases, caching, orchestration with Kubernetes) and to automate it with CI/CD pipelines on GitHub and GitLab.

Specializing in cybersecurity took that practice towards a DevSecOps approach: embedding controls into the development cycle itself, with code analysis, dependency scanning and container review before anything reaches production.

Then I learned to defend what I had built.

I have built complete Blue Team environments: SIEM with Wazuh and its detection rules, response automation through SOAR, OPNsense firewalls, EDR and VPN, plus honeypots exposed to the internet. Coming from systems administration gives me an edge here: once you know what a healthy machine looks like, you spot what falls outside the norm much sooner.

But what really hooks me is what happens after the attack.

My honeypot takes real intrusion attempts every day, and each one leaves a trail to reconstruct: where it got in, which commands it ran, what it downloaded and how far it went. For that I rely on memory analysis and the MITRE ATT&CK framework, which lets me classify every move by known tactics and techniques.

And what comes out of it doesn't stay in the lab: I report the attacking IP addresses and upload the malware samples to public threat intelligence platforms, including several binaries no antivirus engine had recorded before.

In fact...

Latest trainingSpecialization course in IT cybersecurity (EQF 5C)
Prior trainingHigher Technician in Network Systems Administration (EQF 5)
FocusDFIR, SOC, Secure infrastructure
LanguagesSpanish nativeBulgarian nativeEnglish C1–C2French A1Russian A1

Let's talk achievements and numbers:

+12,000
IPs reported
AbuseIPDB
+8
IOCs reported
ThreatFox
+44
Binaries uploaded
MalwareBazaar

Figures gathered from my own honeypots and labs, current as of August 2026. Happy to go into detail on any of these contributions.

Technical skills

SOC & Incident Response

WiresharkWazuhSuricataCowrieMITRE ATT&CKT-Pot

Digital Forensics

Volatility 3CAINEFTK ImagerEric Zimmerman toolsAutopsy

Hardening, Compliance & Governance

CryptographyLinux Server HardeningWindows HardeningISO 27001ENSNIS2GDPR

Networking & Network Security

OPNsensePi-holeBIND9VPNTCP/IPCisco CCNAv7

DevSecOps & Infrastructure

AWSAzureIAMPrometheusGrafanaCentreonGitHubMySQLGitLab CI/CDKubernetesEKSPython
MariaDBGitLabOracle SQLBashAKSJenkinsJavaScriptPL/SQLGitPHPDockerGitHub ActionsAnsibleMavenTerraformAgile ScrumSonarQubeTrivyOWASP ZAPSnykELK (Elasticsearch, Logstash and Kibana)OWASP Top 10

Soft Skills

TeamworkProblem solvingAttention to detailStress management under pressure

Ethical Hacking

nmapKali LinuxBurp SuiteMetasploitgobusterNessus

Experience

03/2024 – 06/2024

Cloud & Infrastructure Internship

Capgemini
  • Developed PL/SQL solutions through Database Shadowing, using Oracle SQL Developer and managing databases such as Exadata and GoldenGate.
  • Monitored Azure instances with Prometheus, Centreon and Grafana.
  • Systematically documented installation, configuration and monitoring procedures.
  • Participated in Agile Scrum, with weekly sprint reviews and retrospectives.

Certifications

CCNAv7

Cisco
View credential ↗
09/2023

Certified Kubernetes Administrator (CKA)

Udemy
View credential ↗
08/2024

DevOps: Beginner to Advanced

Udemy
06/2024

Projects

Security, Honeypots

Proyecto: Dirtylands

Esto es Dirtylands, un proyecto Cowrie + Dionaea cuya propuesta de valor es su rápido despliegue, cuenta con: comandos funcionales, un entorno realista, rigurosidad y madurez del proyecto. Además con plena capacidad de reportar cada evento vía telegram y las maldades a sus respectivas plataformas y la observabilidad.

Cowrie, Dionaea, Python, Telegram, AbuseIPDB, ThreatFox, MalwareBazaar, URLhaus
Coming soon...
Security, Azure

Cowrie Honeypot

Honeypot deployed on Azure with dynamic port knocking via iptables and real-time Telegram alerts.

Cowrie, iptables, Telegram, Azure
View project →
CI/CD, DevSecOps, GitLab

CI/CD DevSecOps Pipeline on GitLab

Full DevSecOps pipeline on GitLab CI/CD, integrating SonarQube, GitLeaks, Snyk, and OWASP ZAP for end-to-end code quality and security scanning. Automated real-time pipeline status notifications are sent via Discord.

CI/CD, GitLab, SonarQube, GitLeaks, Snyk, Zap, Discord
View project →
Cloud, AWS

Multi-tier Web App on AWS (Lift & Shift)

Lift & shift migration of a locally built multi-tier Java web app to AWS (IaaS). Tomcat app servers behind an Elastic Load Balancer with Auto Scaling, MariaDB, Memcached and RabbitMQ as backing services, private DNS on Route 53, artifacts deployed from S3 and access scoped with IAM.

EC2, ELB, Auto Scaling, Route 53, S3, IAM, Tomcat, MariaDB, Memcached, RabbitMQ
View project →