siavash@portfolio:~$cat portfolio.md
reading profile...loading projects...opening portfolio.
portfolio.md
1siavash@portfolio:~$ cat portfolio.md

# about

Cybersecurity Engineer

Selected projects, lab work, and focused consulting.

I work where security operations and infrastructure meet. My experience spans identity, email, endpoints, firewalls, cloud services, SIEM integrations, and incident recovery. I document how systems fail, what the evidence showed, and how the result was verified. I studied physics and mathematics at university; the habit stayed with me: define the system, measure what matters, and test the explanation. Linux is my daily driver.

350+ organizations supported300+ security environments reviewedcross-domain identity · endpoint · network · cloud

# selected projects

PROJECTS / 01–06

Selected work

Technical investigation and governance work, documented as readable case studies with evidence, limits, and business context.

AZURE RBAC / PIM AUDITNEW · SEPTEMBER 2026

The Privilege Audit: following the Azure access trail

A completed five-stage audit of repeated Owner grants, an orphaned Reader assignment, PIM eligibility, temporary resource access, and a condition attached to the final Owner finding.

  • Azure RBAC
  • PIM
  • KQL
  • Least privilege
open project
ENTRA ID INVESTIGATION12 MIN READ

Reconstructing a five-stage OAuth consent-phishing kill chain

A live training-tenant investigation tracing a stolen user session through app-only privilege, a rogue ownership pivot, a custom API scope, and an illicit delegated grant.

  • Microsoft Entra ID
  • OAuth
  • App registrations
  • Identity response
open project
AZURE GOVERNANCE INVESTIGATION8 MIN READ

Tracing unauthorized Azure provisioning to a detective-only policy

A live training-tenant investigation using resource metadata, ARM deployment history, and Azure Policy to explain why a non-compliant environment was detected but not blocked.

  • Azure Policy
  • ARM
  • RBAC
  • Cloud governance
open project
HOME SIEM / HONEYPOT25 MIN READ

Home SIEM with Cowrie, Splunk detections, and an analyst dashboard

A loopback-only Cowrie sensor, containerized Splunk pipeline, synthetic endpoint telemetry, detections, dashboard design, and a full investigation workflow from signal to response.

  • Splunk
  • Cowrie
  • Detection engineering
  • QEMU/KVM
open project
GRC CASE STUDYREADINESS ASSESSMENT

NIST SP 800-171 Rev. 3 readiness assessment for a fictional aerospace contractor

A synthetic CUI readiness project connecting scope, evidence, risk scoring, executive communication, and a measurable POA&M roadmap. The page hands off to a separate incident-response follow-up.

  • NIST SP 800-171
  • CUI
  • Risk register
  • POA&M
open project
FOLLOW-UP CASE STUDYREADINESS → RESPONSE

Incident-response program for the Asterion CUI operating model

The operational follow-up: architecture, Entra and FortiGate containment, Windows response, Splunk evidence, Datto recovery, provider handoffs, five playbooks, case records, and a tabletop exercise.

  • Incident response
  • Entra
  • Splunk
  • Datto
  • Tabletop
open follow-up

# consulting / contact

FOCUSED ENGAGEMENTS

Bring me a concrete security problem.

I provide scoped, project-based consulting for small through enterprise organizations, internal IT teams, security teams, and MSPs. The result is prioritized findings, practical next steps, and documentation your team can use.

security posture reviewsSIEM & telemetry validationidentity & email hardeningfirewall & network reviewincident readiness & recoverysecurity operations runbooks
$ xdg-email "setesham (at) proton (dot) me"consulting email
$ xdg-open linkedin.com/in/siavasheteshamstart a conversation ↗