Security operations, detection engineering and Windows software.
I build defensive tools and practical applications, with a focus on clear evidence, useful diagnostics and understandable controls. My work spans incident investigation, reproducible security labs and products for creators, digital agencies and Windows users.
Explore products · Security projects · Skills and tools · Get in touch
Verified Windows releases: PC Tweaker 1.9.0, Redaxa 0.3.3 and Redexa Social 1.9.3 carry timestamped Certum signatures identifying Aurelio Avila as publisher. See the signing status and verification guide, including the unsigned PC Tweaker Uninstaller 0.8.2 exception.
|
Website security monitoring and client-ready reporting for digital agencies. Glarion identifies meaningful changes, turns technical findings into clear deliverables and requires current proof of domain control before active scans. Product site and current plans Check a website without an account · View the sample report · Read the security model |
Windows performance, gaming, privacy and maintenance tools with reversible tweaks and recovery features. Review each action and its requirements before applying system changes. |
|
Catches secrets, credentials and personal data in text before it is pasted into ChatGPT, Claude, Gemini or Copilot. Scanned on our backend, never sent to an AI provider — details in the privacy section. Desktop app, browser extension and web version |
Local-first creator analytics for YouTube, Instagram, TikTok and X, subject to platform permissions and API availability. Analytics history stays on your device. Account connections and optional paid features use the services described in the privacy policy. |
|
Practice tests for IT certification exam prep (Security+, CySA+ and other vendor tracks), built to mirror real exam format and scoring. |
|
Explore detection tools, investigation walkthroughs and documented labs. Repository READMEs explain the available evidence, sample data, test commands and limitations so you can evaluate each project directly.
| Project | What it does |
|---|---|
| detection-engineering-rules | YARA and Sigma rules, each checked against true and false positive cases. Sigma is compiled to real Splunk SPL with pySigma rather than validated as YAML. |
| network-traffic-analysis | Scapy PCAP analyser for port scans, C2 beaconing and floods. A statistical baseline catches slow floods that fixed thresholds structurally cannot, with a side-by-side demo showing the difference. |
| malware-triage-hash | Hash reputation joined to behavioural scoring, so an unknown sample is not read as a clean one. Ships a Sentinel KQL hunt. |
| ransomware-dfir-timeline | Process, Prefetch, Registry and filesystem artifacts correlated into a single timeline, from the opened attachment to mass encryption, with root cause and detection gaps. |
| phishing-email-analysis | Parses raw .eml, extracts headers, URLs and attachment hashes, flags typosquatting and urgency patterns, enriches through VirusTotal. |
| splunk-brute-force-detection | SPL detections for brute force and password spraying in Windows Security logs, with threshold tuning notes and a triage playbook. |
| soc-home-lab | Wazuh and OpenSearch lab: custom rules, agent deployment, ingestion validation, and the full path from alert to incident report. |
| dma-guide | Reference on DMA attack mechanics and the controls that stop them, from IOMMU and VT-d to Kernel DMA Protection. |
The incident and detection projects include MITRE ATT&CK context where applicable.
SOC analyst, currently Tier 1, handling alert triage, log correlation and detection tuning across Microsoft Sentinel, Splunk and Wazuh.
Certifications and course credentials
| Area | Skills, platforms and tools |
|---|---|
| Security operations | Alert triage · Incident investigation · Log correlation · Threat hunting · Detection tuning · Escalation and incident reporting · SOAR playbooks |
| SIEM and detection | Microsoft Sentinel · KQL · Splunk · SPL · Wazuh · OpenSearch · Sigma · YARA · pySigma · MITRE ATT&CK |
| DFIR and malware analysis | Windows event analysis · Process, Prefetch, Registry and filesystem artifacts · Timeline reconstruction · Hash reputation · Behavioural triage · VirusTotal API · Sandbox evidence |
| Network and email security | Wireshark · Scapy · PCAP analysis · Traffic baselining · Port-scan, beaconing and flood detection · Email header analysis · IOC extraction and enrichment |
| Application and AI security | Nuclei · SSRF protection · Domain ownership verification · Secret and PII detection · Data-loss prevention · LLM security · MCP fundamentals |
| Software development | Rust · TypeScript · Python · JavaScript · SQL · React · Tauri · FastAPI · Axum · PostgreSQL · REST APIs |
| Platforms and identity | Windows 10/11 · Linux and Ubuntu · Microsoft Azure · Microsoft Entra ID · Microsoft Store · winget |
| Engineering workflow | Git · GitHub · GitHub Actions · CI/CD · Automated testing · Visual Studio Code · Security scanning · Release automation |
| Threat-intelligence frameworks | STIX/TAXII · Pyramid of Pain · IOC lifecycle · Behaviour-to-technique mapping |
The technologies above are reflected in shipped products, reproducible security labs or day-to-day security operations.
Languages — Italian (native), English (C1), French (B2), Spanish (B1)
aurelio_11@outlook.it · Amsterdam
Happy to talk about any of the products above, and open to security engineering work.



