SOC Tier 2 Analyst · CS Student @ Holon Institute of Technology
I work in security operations - alert investigation, incident response, and detection engineering across Splunk and CrowdStrike. Outside of work I build tools, mostly Python, mostly security-related.
Agent-based home Security Operations Center for macOS. A local agent collects security events (process executions, network connections, auth attempts, privilege escalations) and streams them to a FastAPI backend that runs a YAML detection rule engine. A React/TypeScript dashboard shows a live event feed, agent management, and per-agent rule config. Runs locally - no cloud required.
Python · FastAPI · React · TypeScript · SQLite · Docker Compose · GitHub Actions
(built to support SOC work)
Monitors open-source threat-intel channels, classifies messages against YAML rules, and uses Gemini AI to filter for active in-the-wild exploitation only. Sends HTML email reports with defanged IOCs and a CSV attachment for ingestion.
Python · Gemini AI · Docker · HashiCorp Vault · Gmail OAuth
| Project | Tech |
|---|---|
| flight-price-checker | Python · Amadeus API · SMTP |
| stock-market-viewer | Python · Tkinter · Requests |
| spotify-release-radar | Python · Spotipy · OAuth |
| multi-user-chat-server | Python · sockets · threading |
