Skip to content
View scott-renny's full-sized avatar

Block or report scott-renny

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
scott-renny/README.md

Scott Renny

Security+ Certified · AWS Certified AI Practitioner · Cybersecurity Engineering · Security Operations

I build, secure, monitor, recover, and document real infrastructure in a continuously evolving home Cyber Operations Center.

CompTIA Security+ AWS Certified AI Practitioner COC Phase 8 complete Current milestone Linux Mint migration LinkedIn


About me

I hold CompTIA Security+ and AWS Certified AI Practitioner certifications, and I am building toward a security operations role through hands-on engineering.

My portfolio goes beyond installing tools. Each major project documents the architecture, security decisions, implementation, validation evidence, failure modes, recovery procedures, and lessons learned behind the finished system.

My working method is simple:

Plan → Build → Secure → Validate → Monitor → Recover → Document → Improve

Portfolio snapshot

Area Current evidence
Security operations Wazuh endpoint monitoring, alert analysis, Sysmon telemetry, MITRE ATT&CK context, malware remediation
Infrastructure security Hardened Ubuntu Server, Windows endpoint baselines, Docker segmentation, private HTTPS administration
Network security WireGuard, Pi-hole DNS policy, UFW, device discovery, network metadata, access-control design
Observability Zeek, Prometheus, Grafana, Graylog, centralized Windows and Linux telemetry
Recovery engineering Automated rsync and Restic backups, encrypted retention, integrity checks, representative restore validation
Automation Python, PowerShell, Bash, systemd, scheduled jobs, REST APIs, GitHub workflows
Engineering governance ADRs, risk registers, change control, evidence handling, validation gates, completion records

Flagship program

A structured 26-phase program documenting the design and operation of an enterprise-inspired Cyber Operations Center.

Completed through Phase 8:

  • program governance, risk management, and documentation standards;
  • clean-slate Ubuntu Server foundation and base hardening;
  • Docker platform security and private management access;
  • WireGuard, Pi-hole, Wazuh, ClamAV, and scoped firewall controls;
  • encrypted, monitored, and restore-tested backup infrastructure;
  • NET-WATCH network visibility and profile-based DNS enforcement;
  • Zeek, Prometheus, Grafana, and Graylog telemetry; and
  • Windows, laptop, phone, and tablet endpoint engineering.

Current milestone: Phase 8.5 — Linux Mint Cinnamon Migration

Project Cerberus delivers this workstation as the Linux Mint Cinnamon engineering platform and primary COC control node.

The next workstation will be built from verified Linux Mint Cinnamon installation media with Secure Boot, full-disk encryption, AppArmor, UFW, selective restoration, Wazuh monitoring, application acceptance testing, and a validated Linux Mint backup before the legacy Windows system is retired.


Featured repositories

These six repositories are the curated entry points to my current portfolio.

Repository What it demonstrates Core technologies
Cyber Operations Center Engineering Program Phased security-operations program spanning infrastructure, endpoints, telemetry, recovery, and governance Wazuh · Zeek · Docker · Linux · Windows
NET-WATCH Operational network visibility and profile-based DNS access control Python · Flask · Pi-hole · Nmap · Wazuh
Project Hermes Repeatable Windows provisioning, validation, backup, restoration, and maintenance PowerShell · Pester · Windows Security
Project Daedalus Self-hosted automation and intelligence workflows with explicit governance n8n · APIs · JSON · Automation
Project Cerberus Linux Mint Cinnamon engineering workstation and primary COC control-node build Linux Mint · Cinnamon · AppArmor · UFW
Security+ Trainer Browser-based study tools, exercises, and mock examinations HTML · CSS · JavaScript · Security+

Additional engineering work

Project Focus
Project Ares Isolated adversary simulation and detection validation
Project Apollo Samsung mobile-device security hardening and validation
Project Atlas Linux infrastructure hardware restoration and reliability
Pi-hole DNS Infrastructure DNS filtering, policy enforcement, and resilient name resolution
Home Lab Network Security Network architecture, segmentation, secure administration, and defensive controls
HomeSOC Preserved SOC-oriented home-lab engineering
Backup Lab Preserved Linux backup automation and recovery engineering
Legacy Project Archive Earlier work showing the progression of my engineering practices

Technical toolkit

Domain Technologies and practices
Operating systems Ubuntu Server, Windows 10/11, Linux Mint Cinnamon
Security and telemetry Wazuh, Sysmon, Zeek, Suricata, ClamAV, Graylog, MITRE ATT&CK
Infrastructure Docker, Docker Compose, Dockge, systemd, Caddy, Samba, virtualization
Networking TCP/IP, DNS, DHCP, Pi-hole, WireGuard, UFW, Nmap, segmentation concepts
Observability Prometheus, Grafana, structured logs, health checks, operational dashboards
Automation and development Python, PowerShell, Bash, Flask, REST APIs, HTML, CSS, JavaScript
Recovery Restic, rsync, retention policies, integrity checks, hash comparison, restore testing
Engineering practice Architecture decisions, risk analysis, change control, evidence handling, runbooks

Current direction

  • Completing the Linux Mint replacement-workstation migration plan
  • Expanding detection engineering and threat-hunting skills
  • Developing incident-response and digital-forensics workflows
  • Building identity-security and Active Directory experience
  • Strengthening cloud and AWS security fundamentals
  • Preparing for an entry-level SOC Analyst opportunity

Professional highlights

  • CompTIA Security+ certified
  • AWS Certified AI Practitioner (AIF-C01), earned August 29, 2026
  • Amazon Information Security Analyst Program graduate through Correlation One
  • Graduated with Honors and a 96% final average
  • Building a public, validation-driven cybersecurity engineering portfolio
  • Interested in SOC analysis, infrastructure security, detection, and incident response

Connect

I welcome conversations with SOC analysts, cybersecurity professionals, infrastructure engineers, recruiters, and people who learn by building.

Connect with me on LinkedIn · Read my engineering journal · Explore all repositories


Build deliberately. Validate continuously. Document everything.

Popular repositories Loading

  1. secplus-trainer secplus-trainer Public

    Interactive CompTIA Security+ study and assessment trainer.

    HTML 2 1

  2. cyber-operations-center-engineering-program cyber-operations-center-engineering-program Public

    Phased Cyber Operations Center engineering program covering networking, SIEM, backup, endpoints, and security operations.

    HTML 2

  3. homesoc homesoc Public

    Legacy cybersecurity engineering project documenting the design and deployment of a self-hosted Security Operations Center using Ubuntu, Docker, Wazuh, CrowdSec, ModSecurity, and Nginx.

    Shell

  4. pihole-dns-infrastructure pihole-dns-infrastructure Public

    Legacy infrastructure engineering project documenting the deployment of a Docker-based Pi-hole DNS sinkhole integrated with Wazuh SIEM, ModSecurity, and Nginx in a multi-service Ubuntu Server envir…

    Shell

  5. backup-lab backup-lab Public

    Legacy infrastructure project documenting Linux backup automation with rsync, Restic, Samba, Cron, and Wazuh.

    Shell

  6. home-lab-network-security home-lab-network-security Public

    Legacy infrastructure engineering project documenting the design and implementation of a software-defined network security architecture using Ubuntu Server, Suricata IDS/IPS, WireGuard VPN, Wazuh S…

    Shell