Skip to content
View b0n60's full-sized avatar

Block or report b0n60

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
b0n60/README.md
██████╗  ██████╗ ███╗   ██╗ ██████╗  ██████╗
██╔══██╗██╔═══██╗████╗  ██║██╔════╝ ██╔═══██╗
██████╔╝██║   ██║██╔██╗ ██║███████╗ ██║   ██║
██╔══██╗██║   ██║██║╚██╗██║██╔══██╗ ██║   ██║
██████╔╝╚██████╔╝██║ ╚████║╚██████╔╝╚██████╔╝
╚═════╝  ╚═════╝ ╚═╝  ╚═══╝ ╚═════╝  ╚═════╝
        b0n60 · Johannesburg, ZA

LinkedIn GitHub SOC Analyst Full Stack Wazuh ZA Press


> whoami --verbose

profile = {
    "handle"      : "b0n60",
    "roles"       : ["SOC Analyst", "Full Stack Developer"],
    "company"     : "Jolinkomo Tech Solutions",
    "location"    : "Johannesburg, Gauteng, South Africa 🇿🇦",
    "focus"       : [
                      "Blue Team Operations",
                      "Detection Engineering",
                      "Custom SIEM / XDR",
                      "Threat Hunting",
                      "Full Stack Secure Application Development"
                    ],
    "cert"        : "Wazuh Certified Engineer (Official)",
    "press"       : ["Sunday Times / TimesLive", "MyBroadband — 2022"],
    "research"    : "R18bn ZA government cybersecurity spending gap — documented & verified",
    "languages"   : ["Python", "JavaScript", "HTML/CSS", "Rust", "C"],
    "tools"       : ["Wazuh", "Graylog", "LibreNMS", "Suricata", "Zeek", "MISP"],
    "ethos"       : "Build it. Open it. Move forward."
}

> cat mission.txt

South Africa is not a peripheral target. It is a primary one.

Ranked among the most attacked nations on the African continent — government portals, financial institutions, healthcare systems, and state security infrastructure face daily, relentless intrusion attempts. In 2022, research conducted under Umboko Sec and independently verified by Sunday Times and MyBroadband established a documented shortfall of at least R18 billion in government cybersecurity spending. A gap that compounds every year accountability remains absent.

The 2025 Gauteng Provincial Government breach — 3.67 million files, 3.8TB of citizen data, healthcare records, housing applications, and economic development information listed at $25,000 on dark web markets — is not an isolated failure. It is the predictable outcome of structural underinvestment.

My work is about closing that gap. Building detection tooling. Hardening networks. Delivering full-stack applications that are secure by design, not by afterthought. Five years in the trenches. Still going.


> neofetch

         #####          OS: Ubuntu 25.04 x86_64
        #######         Theme: Juno-ocean-v40 [GTK2/3]
        ##O#O##         Icons: Papirus-Dark [GTK2/3]
        #######         Terminal: gnome-terminal
      ###########       CPU Usage: 462%
     #############      Disk (/): 126G / 234G (57%)
    ###############
   #################
  ###################

> ./coverage-report --framework mitre --env za-gov

[LOADED] wazuh-rules-za.xml          →  847 custom rules
[LOADED] graylog-pipelines.json      →  124 processing pipelines
[LOADED] librenms-alerts.conf        →  63  alert thresholds

Tactic                    Coverage    Notes
────────────────────────────────────────────────────────────────────
Reconnaissance            ████████████  94%   Passive + active scan detection
Initial Access            ████████████  94%   Web exploit, phishing, cred stuffing
Execution                 ███████████░  88%   Script-based + LOLBin detection
Persistence               ███████████░  88%   Scheduled tasks, registry, services
Privilege Escalation      ██████████░░  82%   Local + domain escalation paths
Defence Evasion           ██████████░░  79%   ← Active development
Credential Access         ████████████  91%   Mimikatz, LSASS, hash harvesting
Discovery                 ████████████  90%   Internal recon detection
Lateral Movement          ██████████░░  83%   SMB, RDP, WMI monitoring
Collection                ████████████  90%   Data staging detection
Exfiltration              ████████████  91%   DNS tunnelling, HTTPS exfil, cloud sync
Command & Control         ██████████░░  84%   Beacon detection, C2 patterns
Impact                    ████████████  92%   Ransomware, wiper, destruction
────────────────────────────────────────────────────────────────────

> cat skills.json

🛡️ Blue Team & Detection

Wazuh Graylog LibreNMS MITRE Suricata Zeek Threat Hunting Incident Response

💻 Full Stack Development

Python JavaScript HTML5 CSS3 Rust C Node.js

🏗️ Infrastructure & Tooling

Linux Docker PostgreSQL Nginx Wireshark Git MISP


> ls ./custom-tools/

Built for environments where commercial and open-source platforms don't fit. South African infrastructure has unique constraints — load-shedding, bandwidth limits, legacy systems — that generic tooling misses.

Tool Replaces Description Stack
🛡️ SentinelCore Wazuh (low-resource) Lightweight SIEM engine with ZA-specific threat intel feeds. Runs on machines Wazuh would bring to their knees. Python · Rust · SQLite
📋 LogHound Graylog High-noise, low-bandwidth log aggregator. Built-in parsers for South African ISP log formats that Graylog doesn't ship with. Python · Redis · FastAPI
📡 NetPulse LibreNMS Modular NMS with non-standard topology support. WhatsApp + SMS alerting for teams without 24/7 NOC coverage. Python · C · SNMP
🗺️ ThreatMapper ZA Manual IOC triage MISP + OTX + curated local feeds. Enriches Wazuh alerts with SA-specific IOC context that global feeds miss entirely. Python · MISP · OTX

Most repositories on this profile are intentional open builds — prototypes and proof-of-concepts left accessible for others to continue. Knowledge transfer matters more than attribution. Take what is useful.


> cat press-citations.txt

In May 2022, research conducted under Umboko Sec was independently verified by Sunday Times and MyBroadband during national coverage of the SpiderLog$ disclosure — a coordinated exposure of vulnerabilities in South African defence, state security, and government digital infrastructure.

"Umboko Sec director Bongo Sijora told Sunday Times their research showed a shortfall of at least R18 billion in government spending on securing national key points and departments from cyber threats."

— Sunday Times / TimesLive, 29 May 2022 · Lax Cybersecurity Leaves SA a Playground for Hackers

"The paper verified the group's claims with cybersecurity firms WolfPack Information Risk and Umboko Sec."

— MyBroadband, May 2022 · Cyril Ramaphosa's Private Data Hacked

Context: SpiderLog$ used President Ramaphosa's personal data to expose how South Africa's government digital infrastructure could be mapped and accessed with minimal effort. The Sunday Times called SA "a playground for hackers". The research Umboko Sec contributed demonstrated this was not rhetorical — it was a documented, costed reality.


> cat za-incidents.log

Date        Target                  Incident
──────────────────────────────────────────────────────────────────────────
2021-07     Transnet                Ransomware — port systems offline, shipping paralysed
2021-09     Dept of Justice         Ransomware — all systems locked, courts and prosecution halted
2022-03     TransUnion              Breach cascaded to President Ramaphosa personal data exposure
2022-05     Dept of Defence / SSA   SpiderLog$ accessed military and state security webmail — verified Umboko Sec
2024        CIPC                    Full DB access since 2021 — plain text passwords, director manipulation possible
2025-03     SA Parliament           Social media hijacked for $Ramaphosa crypto token fraud
2025        Gauteng Gov             3.67M files, 3.8TB citizen data — healthcare, housing on dark web @ $25,000

> ./github-stats.sh


> cat character.md

🧠 Intellectual Range — Draws connections between cybersecurity, genetics, philosophy, and political systems. Approaches security not as a technical exercise but as a discipline with human, societal, and structural dimensions.

🎯 Precise Under Pressure — Cited by national media during a live government breach crisis. Delivers structured, evidence-based analysis when others speculate. Calm is the strategy.

🔨 Builder Mentality — Most repositories are intentional open builds left accessible for the community to extend. Knowledge transfer matters more than attribution.

🌍 Mission-Driven — The infrastructure that ordinary South Africans depend on — healthcare portals, housing systems, government services — deserves to be genuinely secure against real, present threats. That is the work.


> cat connect.yml

contact:
  linkedin   : https://www.linkedin.com/in/bongo-sijora/
  github     : https://github.com/b0n60

open_to:
  - blue team tooling collaboration
  - detection engineering projects
  - south african threat intelligence sharing
  - full-stack secure application development
  - cybersecurity research and press engagement
  - speaking on the ZA threat landscape

// b0n60
// SOC Analyst · Full Stack Developer
// Jolinkomo Tech Solutions · Johannesburg, South Africa 🇿🇦
// Securing the infrastructure that millions depend on
// Built with precision. Hardened by experience. Open by principle.

Profile views

Pinned Loading

  1. PayloadsAllTheThings PayloadsAllTheThings Public

    Forked from swisskyrepo/PayloadsAllTheThings

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    Python

  2. PowerShell PowerShell Public

    Forked from fleschutz/PowerShell

    500+ PowerShell Scripts (.ps1)

    PowerShell 1