Security-minded developer | Web security, incident response & automation — using AI to build faster, not to replace understanding.
I build real systems that solve real problems — attendance, payments, hardware interfaces — with security baked in from the start. When something goes wrong, I want to be the one who finds out why.
I use AI as a tool to accelerate development, not as a shortcut around fundamentals.
| What I Explore | Tools I Use | Goal |
|---|---|---|
| Web Security | Burp Suite / Wireshark / Nmap | Find and fix vulnerabilities |
| Linux & Hardening | Kali Linux / Debian / Lynis | Build secure systems |
| Backend & Auth | Laravel / PHP / Python | Secure authentication flows |
| IoT & Hardware | ESP32 / NodeMCU / RFID | Harden hardware interfaces |
| Incident Response | Kaspersky KRD / Debian Live / Regipy | Endpoint triage & forensics |
| Project | What it does | Security aspect |
|---|---|---|
| restusec-rescue | Anti-malware rescue toolkit — endpoint triage, quarantine, offline forensics | Heuristic detection, dead-box triage, MITRE ATT&CK mapping |
| absensi-murid | Student attendance — QR scan, dashboard, auto-export | Session auth, rate limiting, input validation |
| absensi-guru | Teacher attendance — QR scan, dashboard, auto-export | Access control, secure QR generation |
| tu-yamasy | School payment system with QRIS verification | OTP, payment validation |
| absensi-rfid | RFID-based hardware attendance interface | Hardware auth, card mapping |
Learning by contributing to projects I actually use:
- statewave — AI memory runtime, added unit tests
- prd-maker — AI-assisted PRD tool, fixed linter bug
- okto-pulse — AI project management tool, fixed dev setup
- 🔐 Learning web security — PortSwigger Web Security Academy
- 🛡️ Building toward SOC Analyst path
- ⚙️ Automating incident response workflows
- 📡 Exploring network traffic analysis
- 🌱 Contributing to open source
