Cloud Security β’ Security Operations β’ GRC β’ Networking β’ Linux β’ Security Automation
I am a BS Information Technology student building practical skills in Cloud Security, Security Operations, Governance, Risk & Compliance (GRC), Networking, Linux, and defensive security engineering.
My approach is hands-on: I build, test, document, and improve security-focused systems to understand how security controls work in practice.
My current interests include:
- βοΈ Cloud Security
- π‘οΈ Security Operations & Defensive Security
- π Governance, Risk & Compliance (GRC)
- π Networking & Linux
- π Python Security Automation
- π Security Monitoring & Threat Detection
- π€ AI-assisted Security Analysis
- π Security Evidence & Risk-oriented Analysis
Cloud Security
βββ Identity & Access Management
βββ Least Privilege
βββ Security Controls
βββ Logging & Monitoring
βββ Secure Architecture
GRC
βββ Risk Management
βββ Security Governance
βββ Security Controls
βββ Compliance Concepts
βββ Control Mapping
Security Engineering
βββ Security Monitoring
βββ Log Analysis
βββ Threat Detection
βββ Event Correlation
βββ Automation
βββ Defensive Tooling
- Python
- C++
- Java
- SQL / MySQL
- Pandas
- NumPy
- Cloud Security
- Security Operations (SecOps)
- Security Monitoring
- Log Analysis
- Threat Detection
- Event Correlation
- Networking
- Linux
- Security Automation
- Governance, Risk & Compliance (GRC)
- Streamlit
- Ollama
- Retrieval-Augmented Generation (RAG)
- Evidence-grounded AI workflows
- Local LLM applications
- Tool orchestration
- Security-focused application design
- Session and memory management
KiroTrace is an offline-oriented security monitoring and AI-assisted analysis project built to demonstrate practical SecOps, defensive security engineering, evidence-grounded RAG, controlled security tooling, auditability, and security automation.
| Area | Implementation |
|---|---|
| π₯ Log Processing | Local .log and .json security data |
| π Normalization | Unified security event structure |
| π Detection | Rule-based security event detection |
| π Correlation | Event correlation and analysis |
| π¨ Incident Analysis | Security incident assessment |
| π RAG | Evidence-grounded local retrieval |
| π€ Local AI | Ollama-based local LLM |
| π‘οΈ Tool Control | Controlled security tool execution |
| π« Policy Enforcement | Tool intent and policy validation |
| π Auditability | JSONL security audit logging |
| π§ Memory | Session and contextual memory |
| π₯οΈ Interface | Streamlit security assistant |
ββββββββββββββββββββββββ
β Local Log Data β
β .log / .json β
ββββββββββββ¬ββββββββββββ
β
βΌ
ββββββββββββββββββββββββ
β Parser β
β Normalization / Dedupβ
ββββββββββββ¬ββββββββββββ
β
βΌ
ββββββββββββββββββββββββ
β Detection Engine β
β Security Rules β
ββββββββββββ¬ββββββββββββ
β
βΌ
ββββββββββββββββββββββββ
β Correlator β
β Event Correlation β
ββββββββββββ¬ββββββββββββ
β
βΌ
ββββββββββββββββββββββββ
β Incident Engine β
β Assessment & Context β
ββββββββββββ¬ββββββββββββ
β
ββββββββββββββββ΄βββββββββββββββ
βΌ βΌ
ββββββββββββββββββββ ββββββββββββββββββββ
β Local RAG β β Security Tools β
β Evidence Search β β Policy Controlledβ
ββββββββββ¬ββββββββββ ββββββββββ¬ββββββββββ
β β
βΌ βΌ
ββββββββββββββββββββ ββββββββββββββββββββ
β Local LLM β β Audit Log β
β Ollama β β JSONL β
ββββββββββ¬ββββββββββ ββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββ
β Streamlit Security UI β
β Evidence-Grounded AI Assistant β
βββββββββββββββββββββββββββββββββββββββ
KiroTrace is designed around:
- Local-first processing
- Evidence before inference
- Controlled tool execution
- Explicit policy enforcement
- Separation of RAG and tool execution
- Security action auditability
- Deterministic fallback behaviour
- Output validation
- Confidence normalization
- Context-aware session memory
Python
Streamlit
Ollama
RAG
Docker
Linux
Git
JSON / JSONL
Local Security Logs
π View KiroTrace
π View Full CyberSecurity Portfolio
Selected project screenshots and implementation evidence are maintained inside the project repository.
For KiroTrace, the evidence includes the project structure, security monitoring interface, analysis workflow, and supporting security functionality.
π View KiroTrace Screenshots & Documentation
My security portfolio contains practical work focused on security monitoring, defensive engineering, networking, automation, and security-oriented application development.
Security Monitoring
β
Log Analysis
β
Threat Detection
β
Event Correlation
β
Incident Analysis
β
Security Automation
β
Evidence-Grounded AI
β
Cloud Security / GRC
π Explore My CyberSecurity Portfolio
- Cloud security architecture
- Identity & Access Management
- Least privilege
- Security controls
- Logging & monitoring
- Secure configuration
- Cloud risk concepts
- Risk identification
- Risk assessment
- Security governance
- Security controls
- Compliance concepts
- Control mapping
- Security documentation
- Security monitoring
- Log analysis
- Detection engineering
- Incident analysis
- Security automation
- Evidence collection
- Defensive tooling
- Computer networking
- Linux
- Containers
- Git & GitHub
- Local development environments
University of Layyah β Pakistan
2024 β 2028
Relevant areas of study include:
- Computer Networks
- Algorithms & Problem Solving
- Programming
- Databases
- Information Technology
- Security-related technologies
Completed coursework covering foundational and practical cybersecurity concepts across a multi-course cybersecurity specialization.
I focus on building projects that demonstrate how security systems actually work, rather than only presenting theoretical concepts.
My workflow:
Understand
β
Design
β
Implement
β
Test
β
Validate
β
Document
β
Improve
For security-focused projects, I pay particular attention to:
- What can go wrong?
- What security control prevents it?
- What evidence demonstrates the control?
- What happens when the control fails?
- Can the behaviour be audited?
- Can the result be reproduced?
| Domain | Focus |
|---|---|
| βοΈ Cloud Security | High |
| π GRC | High |
| π‘οΈ Security Operations | High |
| π Security Engineering | High |
| π Networking | High |
| π§ Linux | High |
| π Python Automation | High |
| π€ AI for Security | High |
| π Risk & Compliance | High |
BS IT Student β’ Cloud Security β’ GRC β’ Security Engineering
Building practical security systems and learning through implementation.