https://github.com/qexa/AI-Security-Governance-Framework
An enterprise-grade, Security-as-Code framework for securing RAG-based AI systems end to end.
This project demonstrates how to operationalize AI security using threat modeling, CI/CD enforcement, adversarial testing, and runtime guardrails with an evidence-first approach aligned to NIST AI RMF and OWASP LLM risks.
Focus areas:
• AI threat modeling (STRIDE for RAG & agents)
• CI/CD policy gates and drift detection
• Adversarial testing and red-teaming
• Runtime hallucination and PII guardrails
• Audit-ready evidence generation
-
MDE-Exfiltration-Hunt-Lab
https://github.com/qexa/MDE-Exfiltration-Hunt-Lab
Simulated Microsoft Defender scenario for suspicious archiving and data exfiltration
Tech: PowerShell -
T1053-Scheduled-Task-Detection-Lab
https://github.com/qexa/T1053-Scheduled-Task-Detection-Lab
Detect malicious scheduled task usage for persistence and escalation
Tech: Python -
usb-exfiltration-threat-hunt
https://github.com/qexa/usb-exfiltration-threat-hunt
Insider USB exfiltration detection with templates and reporting
Tech: PowerShell
- Threat-Hunting-Scenario-Tor-Browser-Detection
https://github.com/qexa/Threat-Hunting-Scenario-Tor-Browser-Detection
Detect and respond to Tor Browser usage in enterprise environments
Tech: KQL / Defender
- azure-kali-offensive-lab
https://github.com/qexa/azure-kali-offensive-lab
Offensive Kali lab in Azure for penetration testing and adversary emulation
Tech: Bash / Azure
- Bitcoin-Mining-Threat-Hunt-Lab
https://github.com/qexa/Bitcoin-Mining-Threat-Hunt-Lab
Detect unauthorized cryptomining activity in enterprise environments
Tech: KQL / PowerShell
I’m always open to collaborating on AI security, threat hunting, automation, and platform engineering projects that solve real-world problems.
Reach out via LinkedIn or explore the repositories above.
Innovation and resilience are built one experiment at a time.