Skip to content
View Elvis-Packet's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Elvis-Packet

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Elvis-Packet/README.md

Hi, I'm Elvis Mbugua πŸ‘‹

Cloud Security Engineer (AWS) Β· I secure what I build

Software developer turned cloud security engineer, based in Nairobi πŸ‡°πŸ‡ͺ. I design and harden secure AWS environments β€” least-privilege IAM, infrastructure-as-code, and automated guardrails β€” and because I came up through engineering, I fix problems in code instead of just flagging them. I also think like an attacker: I pentest the web and API surfaces I defend.

  • πŸŽ“ [Your Degree], KCA University
  • πŸ›‘οΈ Trained across the full security lifecycle through AfricaHackon Academy
  • πŸ”­ Focus: AWS security Β· IAM Β· Terraform / IaC security Β· policy-as-code
  • βš”οΈ Offensive edge: web & API penetration testing (OWASP Top 10, Burp Suite)
  • ✍️ I document real cloud misconfigurations β€” the attack first, then the code that closes it

🧭 What I do

  • Build secure by default β€” least-privilege IAM, hardened Terraform / CloudFormation, encryption everywhere, centralised logging baselines
  • Automate the defense β€” IaC security scanning in CI/CD, policy-as-code, and auto-remediation with Python + Lambda
  • Detect & respond β€” cloud logging, log analysis, and incident response (my blue-team foundation)
  • Attack to validate β€” web & API pentesting to prove the hardening holds against real attack paths

πŸ› οΈ Projects & Writeups

Project What it covers
☁️ flaws.cloud β€” AWS Misconfiguration Walkthrough (Levels 1–6) Exploited public S3 buckets, global AuthenticatedUsers ACLs, AWS keys in Git history, an unencrypted public EBS snapshot, IMDSv1 metadata SSRF, and read-only IAM enumeration β†’ Lambda invocation β€” each finding paired with the AWS control that closes it
βš”οΈ Reconnaissance & Subdomain Enumeration Passive + active subdomain discovery (Subfinder, Dnsenum), deduplicated with Anew, liveness-checked with httpx, and WAF-fingerprinted with wafw00f β€” scripted end to end, narrowing dozens of hosts down to the live, in-scope attack surface
βš”οΈ Wireless Network Auditing & Pentesting Full WiFi attack chain in a virtualized 802.11 lab β€” monitor mode, rogue AP, deauth flood, WPA/TKIP handshake capture, and an aircrack-ng dictionary attack with rockyou
βš”οΈ Windows Exploitation β€” Metasploit + ngrok Exposed a Metasploit listener through an ngrok TCP tunnel, delivered a reverse_http Meterpreter payload to a Windows 10 VM, landed a live session, and ran post-exploitation enumeration β€” isolated lab only
🎯 Financial-Sector Threat Model & Adversary Analysis Direct & indirect targeting factors, supply-chain pivot paths, ranked adversary classes, and capability / timeframe assessment for a Kenyan asset-management firm
🧱 Student Records β€” PHP + MySQL CRUD App Full create / read / update / delete over MySQL using PHP PDO with prepared statements, results rendered in a Bootstrap table

🧰 Tools

Cloud & Infrastructure-as-Code

Scripting & Automation

Offensive (Web / API)

Network & Detection

πŸ“œ Certifications

🎯 Currently pursuing

  • AWS Certified Cloud Practitioner β†’ AWS Certified Security – Specialty
  • HashiCorp Terraform Associate
  • Burp Suite Certified Practitioner (BSCP)

πŸ“Š GitHub Stats

πŸ“« Connect

Pinned Loading

  1. github-profile- github-profile- Public