< 02 / SCOPE >
FOUR PILLARS

What I build & defend.

Practice areas. Locked priority order.

01 / 04

Applied IT, Network & Security competency

Hands-on across enterprise stacks.

Windows Server / Active Directory lifecycle, Cisco IOS networking (VLAN, EtherChannel, inter-VLAN, ACL/NAT), Hyper-V virtualization, web application security testing, penetration testing workflow, SIEM/SOC stack operations. Lab-validated across multiple environments.

hands-on · lab-validated

02 / 04

AI-leveraged knowledge & security workflow

AI as a working discipline, not a slogan.

Multi-MCP agent orchestration, typed auto-memory schemas, multi-tier verification ladders, knowledge graphs over mixed-source corpora. Production-scale workflow on commodity hardware.

orchestration · memory · verification

03 / 04

Security research environment

Multi-cloud, multi-tier, evidence-driven.

Static source review combined with live observable testing. Multi-cloud attack-chain framework across GCP / AWS / Azure. Forensic-trail capture per run. Submission readiness governance: five-stage gate from source-verify to final-verdict.

multi-cloud · multi-tier · live witness

04 / 04

Open-source contributions to security libraries

Upstream PRs into widely-used codebases.

Cryptography (Google Tink ecosystem: Python, Tinkey, C++, Go, Java, AWS-KMS, GCP-KMS, HashiCorp Vault sub-projects), runtime sandbox (gVisor), Bluetooth stack (Bumble), package security (osv-scanner / osv-scalibr), CLI tooling (click).

view merged contributions

crypto · sandbox · package security

< 03 / HANDS-ON CAPABILITIES >
8 OF 8 VERIFIED

Hands-on capability matrix.

$ cat capabilities.tsv | verify

./capabilities · 8 entries · verifiedschema: ID · NAME · TOOLS · STATUS
[01]/08

Windows Server / Active Directory lifecycle

Forest design, DC promotion, GPO authoring & troubleshooting, PowerShell admin tooling.

AD DS · GPO · PowerShell admin · Server 2016 – 2025

VERIFIED
[02]/08

Cisco IOS networking

Switch & router configuration, VLAN/trunk design, link aggregation, inter-VLAN routing.

VLAN / trunk · EtherChannel · inter-VLAN · ACL · NAT

VERIFIED
[03]/08

Hyper-V virtualization administration

Virtual switch design, VHD lifecycle, dynamic memory tuning, multi-VM lab provisioning.

VHD / VHDX · virtual switches · checkpoints · dynamic memory

VERIFIED
[04]/08

Web application vulnerability testing

Manual + automated testing against OWASP Top 10 targets in controlled lab environments.

Burp · ZAP · SQLi / XSS / CSRF / SSRF · gobuster · sqlmap

VERIFIED
[05]/08

Penetration testing workflow

Standard kill-chain: reconnaissance, enumeration, exploitation, post-exploitation.

recon → enumeration → exploitation → post-exploit

VERIFIED
[06]/08

SIEM / SOC stack operations

Tier-1 alert triage methodology, IDS rule analysis, case management workflow.

Wazuh · Security Onion · Suricata · Zeek · alert triage

VERIFIED
[07]/08

AI orchestration

Working agent architecture, not toy demos. Production scale on commodity hardware.

multi-MCP stacks · typed memory schemas · verification ladders

VERIFIED
[08]/08

Open-source security contributions

Sustained upstream PRs into widely-used security libraries.

Tink · gVisor · Bumble · osv-scanner · click

VERIFIED
end of fileexit 0
< 04 / SELECTED WORK >
5 FRAMES · LIVING RECORD

Selected work.

FRAME-01 to FRAME-05 · operator-curated

FRAME-01STRONGMIXED

Living AI-assisted professional knowledge & capability system

Multi-layer architecture. Obsidian vault as source, Claude Code as orchestration, MCP servers (filesystem / REST / browser / web / creative), typed auto-memory with bidirectional vault sync, topic-classified knowledge graph, curated portfolio layer with stage gates. A single operator running an AI-assisted professional workflow at production scale on commodity hardware.

Claude CodeMCPObsidianOllamatyped memorytopic graph
FRAME-02STRONGMIXED

AI-assisted security research and validation environment

Multi-cloud research environment. Static source review combined with live observable testing under multi-tier AI verification (Scout / Judge / Sonnet / Opus). Session Persistence Layer, Attack State Machine, Resource Lifecycle Actions, Multi-Hop Chain Planner across GCP / AWS / Azure. Discovery-aware hunting with forensic-trail capture.

multi-cloudmulti-tier verificationGCP / AWS / Azurelifecycle.jsonl
FRAME-03STRONGPUBLIC

Microsoft 365 security operations toolkit

Open-source PowerShell audit suite for Microsoft 365 and Cloudflare in small organizations. Audits five domains (Sentinel, Defender for Office 365, DNS and email authentication, Entra ID, Defender for Cloud) and produces a P1 / P2 / P3 ranked report with deployable remediation artifacts. Ships Sentinel analytics rule templates, KQL hunting drills, and email authentication baselines covering SPF, DKIM, DMARC, MTA-STS, and TLS-RPT.

view toolkit
M365SentinelKQLSPF / DKIM / DMARCCloudflare
FRAME-04STRONGPUBLIC

Open-source upstream contributions to widely-used security libraries

Open-source security research with focus on Google gVisor (container sandboxing and Linux runtime behavior). Sustained contributions include TOCTOU fixes in systrap, TUN device crash handling, Go concurrency race fixes, guest-writable shared memory hardening. Additional upstream PRs across Google Tink (cryptography), Bumble (Bluetooth stack), osv-scanner (package security), and click (CLI tooling).

view merged contributions
TinkgVisorBumbleosv-scannerclick
FRAME-05STRONGPUBLIC

Cyber Defense Competition — Security Lead

Forty-eight-hour multi-zone blue-team engagement against a live red team at Sierra College Cyber Defense Competition. Deployed Security Onion, Wazuh, Suricata, Zeek, and honeypots across WAN, DMZ, and LAN zones. Authored a Sigma rule pack, hunting queries, and a triage runbook for sustained adversary activity under time pressure. Public case-study repository at github.com/ibondarenko1/blue-team-engagement.

view case study
blue teamSecurity OnionWazuhSigmatriage runbook
< 05 / NOW >
LIVE · 2026-05-12

$ systemctl status now.service
now.service · operator workstream snapshot
    Active: running
    Loaded: research-stack.cfg

Currently.

Running multi-cloud AI-assisted hunts via the ClearAhead pipeline. Paired-session live engine with multi-tier verification across GCP / AWS / Azure. Filing upstream PRs across Tink, gVisor, grpc, Bumble: the current batch covers AWS-KMS / GCP-KMS CRC32C integrity gates, gVisor nvproxy hardening, and grpc RBAC path canonicalization (sibling of CVE-2026-33186).

In parallel: live-fire blue-team practice under sustained operational pressure. Cloud-deployed lab pod with Security Onion 2.4, pfSense + Snort IPS, Wazuh agents, and a mixed Linux / Windows fleet, exercised against simulated adversary activity at production rate. Scope covers SOC alert triage, KQL pivot hunting, MITRE ATT&CK mapping, firewall and IDS tuning under load, and disciplined change management across reset cycles.

Response frameworks layered in as fallback discipline: CIS Critical Controls, NIST CSF, PCI-DSS, and HIPAA technical safeguards. Role spread across firewall, Windows, Linux, application, monitoring, and change-management leads, with shared runbooks for reset recovery and uptime continuity.

STACK · Kali · Claude Code · MCP · ObsidianRIG · COMMODITY · TWO-HOST LAB
< 06 / CONTACT >
END OF FILE

/contact.

Two channels. One filter.

INBOX FILTER

Open for OSS security collaboration, architecture review, full-time opportunities in detection engineering and security operations, and research dialogue. Cold sales routes to /dev/null.

CURRENT STATUS

Selective engagement. Response window 24–72h.

LOCATION

California · Pacific Time.

// IEVGEN BONDARENKO · 2026EOF