Why does this page exist!?
Mark is trying to get a day job in cybersecurity!
This necessitates him building a Github portfolio to show that he kind of knows what he’s doing! Bruno’s CV/Resume
Projects
- Home SIEM Honeypot Investigation — end-to-end investigation of real attacker traffic captured by a self-hosted Cowrie honeypot, correlated through Wazuh, TheHive, and MISP.
- Automated Threat Intelligence Briefing Pipeline — a fully unattended daily threat intel digest built on MISP, a locally-hosted LLM (gpt-oss:20b via Ollama), and systemd, from ingestion through summarization to a scheduled write.
- LLM Prompt Injection Red Team Assessment — automated and manual red-teaming of a wrapped customer-support LLM app across two locally-hosted models, mapped to the OWASP LLM Top 10, showing that generic jailbreak benchmarks don’t predict real data-exfiltration resistance.
What’s Coming
- More technical projects at various points of completion
- CTI/OSINT write-ups (threat actor research, MITRE ATT&CK mapping)
- Pentest lab reports (various experiments)
- GRC toolkit (ISO 27001 templates, NIS2 checklists)
In the Meantime
Head back to my homepage to see some of my other publications! The Moloch has my publicly available threat intel analysis (as well as some spicy opinion pieces). Bruno’s Weird Fiction Project This will be launching in late 2026/early 2027.