UTC —:—:— AVAILABLE FOR ENGAGEMENTS

Bridge log — personal site

Roman

Information Security·Systems & Identity·Merchant Mariner

I'm an IT and information security professional with roots going back to Linux 2.0 — systems administration, DevOps, and infosec across regulated environments, Active Directory, AWS, IAM, Group Policy, and firewall hardening. I currently work rotations as a mariner, and study and build in concentrated bursts between watches. I'm rebuilding a shore-side career in systems administration and information security. My research interests are oriented toward red team and offensive security work, and DFIR, as well as UEFI and hypervisor security where a system's depth becomes an asset rather than a liability.

Focus areas

POSITION
Systems & Identity

Active Directory / Entra / IAM

Hybrid identity, Group Policy, AWS IAM, and firewall hardening across regulated environments.

DFIR

Digital Forensics & Incident Response

Analysis, malware triage, and writing up findings — including active work on a recent attack that has proven to be a rich case study due to the wide range of persistence vectors and EDR evasion that the attacker's malware utilized.

Infrastructure Security

Secure Boot & Hardened Self-Hosting

Trust-chain integrity, reverse proxy hardening, mTLS, and PKI. An example being the design and implementation of a secure vault architecture in AWS serving >700 secrets to all of my devices and machines.

In Progress

Offensive Security

Building a high quality skillset in red team methodologies — Security+ exam scheduled within a few weeks, OSCP/PNPT/eJPT on the roadmap.

Lab log

SELECTED ENTRIES
2026

xenuki

A Rust tool that packs a Xen dom0's initramfs and Xen.cfg as additional PE sections into Xen.efi, so hypervisor and dom0 boot inputs validate as one signed binary under Secure Boot — one artifact, one trust boundary.

RUSTSECURE BOOTXEN
2026

Self-hosted hardened credential vault

Consolidated years of scattered credentials — browser stores, KeePass databases, notes — into a self-hosted vault behind Docker, Postgres, and an nginx reverse proxy. Currently layering in mTLS with CA-issued client certs and DN-based authorization ahead of making it globally reachable, plus automated encrypted backups to S3.

DOCKERNGINXmTLSPOSTGRESQL
2026

Home lab — Xen / Windows Server 2025

Xen hypervisor with a hybrid Gentoo Linux dom0 and domU guests ranging from WS2025 providing AD <-> Entra Connect hybrid topology, Cloud Sync, and Azure Arc onboarding — the proving ground for both the AZ-104 study plan I created and the xenuki EUFI PE32+ binary packer project mentioned above.

XENWS2025AZURE ARC

DFIR writeups (in progress)

Case notes and technique breakdowns — including those from a recent attack analyzed in Ghidra — covering API hashing, reflective loading, and C2 structure identification, write ups will be uploaded to this site when they are complete.

GHIDRAMALWARE ANALYSIS

Certifications

INSTRUMENTS

Connect

TRANSMIT