mariacybersec
Safety-critical thinking, applied to security
AVIATION SECURITY
FLIGHT
DESTINATION
STATUS
AV-001
ACARS DATALINK
Exploring whether detection engineering applies to aviation datalink. Ingesting and baselining lawfully-sourced, decoded ACARS/VDL2 message data.
SHIPPED
DETECTION ENGINEERING
FLIGHT
DESTINATION
STATUS
DE-001
SSH BRUTE FORCE
Splunk workflow to catch brute-force logins. Failed-auth searches grouped by source IP, real-time alerting and a dashboard panel.
SHIPPED
DE-002
DNS EXFILTRATION
Simulated normal and tunneled DNS traffic with Python and Scapy, then analysed entropy and packet behaviour in Wireshark.
SHIPPED
DE-003
THE SILENT SIEM
Post-mortem on why healthy Elastic detections stayed silent during a simulated intrusion chain. Schema drift, stateless logic and a stateful EQL fix.
SHIPPED
DE-004
SENSOR TAMPERING
Python trust engine using EWMA and robust Z-scores to fuse multi-sensor telemetry and catch drift, spoofing and dropout that single-source alerts miss.
SHIPPED
INFRASTRUCTURE
FLIGHT
DESTINATION
STATUS
INF-001
SOC LAB
19-service SOC lab (Elastic, Suricata, Zeek, MISP and more) with a Python status aggregator and iOS Scriptable widget for homescreen visibility.
SHIPPED
THE DEBRIEF
Exploring the critical intersection of Aviation and Cybersecurity, breaking down real-world patterns into short debriefs.