Skip to content
View seyifalode-cmd's full-sized avatar

Block or report seyifalode-cmd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
seyifalode-cmd/README.md

Oluwaseyi Michael Falode · Cloud & Cybersecurity Engineer

Building secure, scalable cloud infrastructure — and hunting the threats that target it.

View Full Project Portfolio →

I work across the full cloud security stack: infrastructure automation with Terraform and Ansible, container orchestration with Kubernetes and Docker, CI/CD pipelines with Jenkins, and proactive threat detection using MITRE ATT&CK-mapped Sigma rules, CrowdStrike Falcon, and Splunk. My projects reflect real-world engineering problems — not tutorials.


What I Work With

Cloud & Infrastructure AWS · Azure · Terraform · Ansible · EC2 · S3 · Lambda · Key Vault · Auto Scaling · Load Balancers

Containers & Orchestration Kubernetes · Docker · Docker Compose · Docker Swarm · Spring Boot on K8s

CI/CD & Automation Jenkins (multi-node, pipelines, Groovy libraries) · Python CD · Infrastructure as Code

Security & Threat Detection Sigma Rules · Detection-as-Code · MITRE ATT&CK · CrowdStrike Falcon · Splunk · Microsoft Sentinel · Elastic SIEM · SOC Monitoring · Threat Hunting · EDR · Azure Key Vault


Featured Projects

Project What It Is
Sigma Detection Rules — 15-Rule ATT&CK Library Production-grade detection-as-code library: 15 MITRE ATT&CK-mapped Sigma rules spanning credential access, lateral movement, exfiltration, persistence, defense evasion, and impact — each with Splunk SPL, Sentinel KQL, and Elastic translations
SOAR Playbooks — SOC Automation Library 4 vendor-neutral SOAR playbooks (phishing response, suspicious login, malware/endpoint isolation, cloud misconfiguration) with Mermaid flowcharts, Python enrichment scripts (VirusTotal, MISP, IP geo), and mandatory human-in-the-loop approval gates mapped to MITRE ATT&CK
Kubernetes Container Security Pipeline Three-layer DevSecOps pipeline: Trivy image scanning + OPA Gatekeeper admission control + Falco runtime threat detection on a live Minikube cluster
CrowdStrike Threat Hunt — SCATTERED SPIDER Hypothesis-driven threat hunt against a real-world eCrime group using CrowdStrike Falcon CQL, mapped to MITRE ATT&CK v14
Wiz + Palo Alto Cloud IR Playbook End-to-end cloud incident response — Wiz Toxic Combination detection (Log4Shell + public S3 + IAM escalation) with Palo Alto Cortex XDR automated containment
Azure Cloud Security Lab Hands-on Azure security lab covering Entra ID, RBAC, Defender for Cloud, Microsoft Sentinel, VNet/NSG, and KQL threat detection
Splunk SOC Monitoring Lab End-to-end SOC monitoring environment built in Splunk with detection rules, alerts, and dashboards
AWS Disaster Recovery Strategy Multi-region AWS DR architecture with RTO/RPO targets and automated failover
Azure Key Vault Lab Secrets management and access policy automation using Azure Key Vault
Kubernetes Rolling Deployment Zero-downtime rolling deployments on Kubernetes with health checks and rollback

Project Categories

Security & Threat Detection

Cloud Infrastructure (AWS & Azure)

Kubernetes & Containers

CI/CD & Jenkins

Ansible & Configuration Management

Terraform & IaC Testing


Currently Working On

  • Detection-as-code: expanding the MITRE ATT&CK-mapped Sigma rule library with Splunk, Sentinel, and Elastic coverage
  • SOAR playbook development: automating SOC response workflows with human-in-the-loop approval gates
  • Cloud security architecture and detection engineering across AWS and Azure environments

View All Repositories

Pinned Loading

  1. sigma-detection-rules sigma-detection-rules Public

    ITRE ATT&CK-mapped Sigma detection rules with Splunk, Sentinel & Elastic conversions

    1

  2. soar-playbooks soar-playbooks Public

    SOAR playbooks for a modern SOC — phishing, suspicious login, malware, and cloud misconfiguration response with enrichment scripts and Mermaid flowcharts

    Python

  3. azure-cloud-security-lab azure-cloud-security-lab Public

    Hands-on Azure security lab — Entra ID, RBAC, Key Vault, Defender for Cloud, Microsoft Sentinel, VNet/NSG, and Azure Monitor with KQL

  4. crowdstrike-threat-hunt-portfolio crowdstrike-threat-hunt-portfolio Public

    CrowdStrike threat hunting portfolio

    2

  5. k8s-container-security-pipeline k8s-container-security-pipeline Public

    Three-layer Kubernetes container security pipeline: Trivy (image scanning) + OPA Gatekeeper (admission control) + Falco (runtime threat detection)

  6. wiz-paloalto-cloud-ir-playbook wiz-paloalto-cloud-ir-playbook Public

    Cloud incident response playbook using Wiz CNAPP and Palo Alto Cortex XDR — Toxic Combination detection on AWS