Skip to content
View hiagokinlevi's full-sized avatar

Block or report hiagokinlevi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
hiagokinlevi/README.md

Hiago Kin Levi

Cyber Ops since 2007. I build defensive security tooling for incident response, DFIR, IAM, AppSec, cloud posture, detection engineering, AI security, containers, secrets, WAFs, phishing monitoring, and applied cryptography.

My official website is hiagokinlevi.com .

My current public portfolio is Cyber Port: a 13-repository defensive security ecosystem released under CC BY 4.0.

Official Links

Cyber Port Live Activity

Last portfolio cycle: Cycle 116, completed on 2026-04-11
Current focus: secret-leak-sentinel
Latest validated adjustment: close the dotenv severity-escalation roadmap item without overstating placeholder environment templates.

What changed recently

  • Hardened classifiers/criticality_classifier.py so live dotenv-family files such as .env, .env.local, .env.production, and config.env are treated as high-risk secret stores even when their suffix is not literally .env
  • Explicitly excluded placeholder dotenv filenames such as .env.example, .env.sample, and .env.template from automatic escalation so documentation and sample templates do not get promoted to CRITICAL by filename alone
  • Added dedicated classifier regressions for live dotenv variants, named *.env files, placeholder dotenv examples, and sample-context placeholders, then refreshed the target README, detection methodology, and roadmap to record the completed item

Portfolio status

  • Portfolio backlog: 120 open roadmap items across 13 repositories.
  • Next completion-first target: secret-leak-sentinel.
  • License baseline: CC BY 4.0 with attribution.

Current publish blocker

  • git push origin main remains blocked in secret-leak-sentinel, k1N-Cyber-Port, and /Users/hiagokin/hiagokinlevi-profile because outbound GitHub DNS is unavailable
  • k1N-Cyber-Port remains locally diverged from origin/main, so direct central publication is still unsafe even after the new target commit
  • The central workspace still carries unrelated local CODE_OF_CONDUCT.md and SECURITY.md edits that should stay out of this cycle's index commit

Next visible focus

  • VS Code extension (calls CLI and surfaces findings inline)
  • ML-based classifier to reduce false positive rate on entropy findings
  • Context-aware analysis (is the file a test fixture? a documentation example?)

Automation policy

Cyber Port runs as a continuous automatic improvement loop. Each cycle updates tests, documentation, portfolio memory, central index status, and this profile activity block without requiring manual launch buttons. If publishing is blocked by a Git divergence or remote issue, the automation records the blocker, avoids force-push, and continues with the next safe validation or improvement path.

Main Repositories

Area Repositories
Threat Detection & Response honeypot-foundry, dfir-attack-lab, ir-playbooks-automation
Application & Web Security waf-defense-rulepacks, secure-pipeline-blueprints, offensive-gvuln
Cloud & Infrastructure Security cloud-posture-watch, iam-audit-lab, container-defense-stack
Identity, Secrets & Monitoring secret-leak-sentinel, phishing-surface-monitor
AI & Cryptography Security ai-security-guardrails, cryptologik

Operating Principles

  • Defensive and authorized security work only.
  • Practical tools with tests, documentation, and repeatable validation.
  • Continuous improvement through numbered Cyber Port cycles.
  • The profile activity updater can fall back to automation memory when central index sync is blocked, keeping the public latest-activity block aligned with the newest validated cycle.
  • The profile activity updater accepts a full ## Cycle N Summary, concise automation-memory completion bullets, or the richer ## Latest Run / ## What This Run Did automation-memory sections, so the public activity block can stay current before central sync finishes.
  • Public educational value without malware, exploit kits, bypass guidance, or unsafe abuse workflows.

Popular repositories Loading

  1. cyber-port cyber-port Public

    Root index for the k1N Cyber Port cybersecurity portfolio — 13 defensive security repositories

    Python 4

  2. secret-leak-sentinel secret-leak-sentinel Public

    Secret detection and prevention for repositories, pipelines, configs, and logs — scan, classify, and prevent credential exposure

    Python 4

  3. honeypot-foundry honeypot-foundry Public

    Defensive honeypots, deception engineering, and attack telemetry collection for blue teams and SOC analysts

    Python 3

  4. dfir-attack-lab dfir-attack-lab Public

    DFIR triage kit and attack analysis lab — collect, correlate, and reconstruct incidents defensively

    Python 3

  5. waf-defense-rulepacks waf-defense-rulepacks Public

    Defensive WAF rule packs for Cloudflare, AWS WAF, Azure WAF, and multivendor hardening baselines

    Python 3

  6. secure-pipeline-blueprints secure-pipeline-blueprints Public

    Secure CI/CD pipeline blueprints for GitHub Actions, GitLab CI, and Azure DevOps with SAST, SCA, secrets scanning, and IaC validation

    Python 3