██████╗ ██████╗ ███╗ ██╗ ██████╗ ██████╗
██╔══██╗██╔═══██╗████╗ ██║██╔════╝ ██╔═══██╗
██████╔╝██║ ██║██╔██╗ ██║███████╗ ██║ ██║
██╔══██╗██║ ██║██║╚██╗██║██╔══██╗ ██║ ██║
██████╔╝╚██████╔╝██║ ╚████║╚██████╔╝╚██████╔╝
╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ╚═════╝ ╚═════╝
b0n60 · Johannesburg, ZA
profile = {
"handle" : "b0n60",
"roles" : ["SOC Analyst", "Full Stack Developer"],
"company" : "Jolinkomo Tech Solutions",
"location" : "Johannesburg, Gauteng, South Africa 🇿🇦",
"focus" : [
"Blue Team Operations",
"Detection Engineering",
"Custom SIEM / XDR",
"Threat Hunting",
"Full Stack Secure Application Development"
],
"cert" : "Wazuh Certified Engineer (Official)",
"press" : ["Sunday Times / TimesLive", "MyBroadband — 2022"],
"research" : "R18bn ZA government cybersecurity spending gap — documented & verified",
"languages" : ["Python", "JavaScript", "HTML/CSS", "Rust", "C"],
"tools" : ["Wazuh", "Graylog", "LibreNMS", "Suricata", "Zeek", "MISP"],
"ethos" : "Build it. Open it. Move forward."
}South Africa is not a peripheral target. It is a primary one.
Ranked among the most attacked nations on the African continent — government portals, financial institutions, healthcare systems, and state security infrastructure face daily, relentless intrusion attempts. In 2022, research conducted under Umboko Sec and independently verified by Sunday Times and MyBroadband established a documented shortfall of at least R18 billion in government cybersecurity spending. A gap that compounds every year accountability remains absent.
The 2025 Gauteng Provincial Government breach — 3.67 million files, 3.8TB of citizen data, healthcare records, housing applications, and economic development information listed at $25,000 on dark web markets — is not an isolated failure. It is the predictable outcome of structural underinvestment.
My work is about closing that gap. Building detection tooling. Hardening networks. Delivering full-stack applications that are secure by design, not by afterthought. Five years in the trenches. Still going.
##### OS: Ubuntu 25.04 x86_64
####### Theme: Juno-ocean-v40 [GTK2/3]
##O#O## Icons: Papirus-Dark [GTK2/3]
####### Terminal: gnome-terminal
########### CPU Usage: 462%
############# Disk (/): 126G / 234G (57%)
###############
#################
###################
[LOADED] wazuh-rules-za.xml → 847 custom rules
[LOADED] graylog-pipelines.json → 124 processing pipelines
[LOADED] librenms-alerts.conf → 63 alert thresholds
Tactic Coverage Notes
────────────────────────────────────────────────────────────────────
Reconnaissance ████████████ 94% Passive + active scan detection
Initial Access ████████████ 94% Web exploit, phishing, cred stuffing
Execution ███████████░ 88% Script-based + LOLBin detection
Persistence ███████████░ 88% Scheduled tasks, registry, services
Privilege Escalation ██████████░░ 82% Local + domain escalation paths
Defence Evasion ██████████░░ 79% ← Active development
Credential Access ████████████ 91% Mimikatz, LSASS, hash harvesting
Discovery ████████████ 90% Internal recon detection
Lateral Movement ██████████░░ 83% SMB, RDP, WMI monitoring
Collection ████████████ 90% Data staging detection
Exfiltration ████████████ 91% DNS tunnelling, HTTPS exfil, cloud sync
Command & Control ██████████░░ 84% Beacon detection, C2 patterns
Impact ████████████ 92% Ransomware, wiper, destruction
────────────────────────────────────────────────────────────────────
Built for environments where commercial and open-source platforms don't fit. South African infrastructure has unique constraints — load-shedding, bandwidth limits, legacy systems — that generic tooling misses.
| Tool | Replaces | Description | Stack |
|---|---|---|---|
| 🛡️ SentinelCore | Wazuh (low-resource) | Lightweight SIEM engine with ZA-specific threat intel feeds. Runs on machines Wazuh would bring to their knees. | Python · Rust · SQLite |
| 📋 LogHound | Graylog | High-noise, low-bandwidth log aggregator. Built-in parsers for South African ISP log formats that Graylog doesn't ship with. | Python · Redis · FastAPI |
| 📡 NetPulse | LibreNMS | Modular NMS with non-standard topology support. WhatsApp + SMS alerting for teams without 24/7 NOC coverage. | Python · C · SNMP |
| 🗺️ ThreatMapper ZA | Manual IOC triage | MISP + OTX + curated local feeds. Enriches Wazuh alerts with SA-specific IOC context that global feeds miss entirely. | Python · MISP · OTX |
Most repositories on this profile are intentional open builds — prototypes and proof-of-concepts left accessible for others to continue. Knowledge transfer matters more than attribution. Take what is useful.
In May 2022, research conducted under Umboko Sec was independently verified by Sunday Times and MyBroadband during national coverage of the SpiderLog$ disclosure — a coordinated exposure of vulnerabilities in South African defence, state security, and government digital infrastructure.
"Umboko Sec director Bongo Sijora told Sunday Times their research showed a shortfall of at least R18 billion in government spending on securing national key points and departments from cyber threats."
— Sunday Times / TimesLive, 29 May 2022 · Lax Cybersecurity Leaves SA a Playground for Hackers
"The paper verified the group's claims with cybersecurity firms WolfPack Information Risk and Umboko Sec."
— MyBroadband, May 2022 · Cyril Ramaphosa's Private Data Hacked
Context: SpiderLog$ used President Ramaphosa's personal data to expose how South Africa's government digital infrastructure could be mapped and accessed with minimal effort. The Sunday Times called SA "a playground for hackers". The research Umboko Sec contributed demonstrated this was not rhetorical — it was a documented, costed reality.
Date Target Incident
──────────────────────────────────────────────────────────────────────────
2021-07 Transnet Ransomware — port systems offline, shipping paralysed
2021-09 Dept of Justice Ransomware — all systems locked, courts and prosecution halted
2022-03 TransUnion Breach cascaded to President Ramaphosa personal data exposure
2022-05 Dept of Defence / SSA SpiderLog$ accessed military and state security webmail — verified Umboko Sec
2024 CIPC Full DB access since 2021 — plain text passwords, director manipulation possible
2025-03 SA Parliament Social media hijacked for $Ramaphosa crypto token fraud
2025 Gauteng Gov 3.67M files, 3.8TB citizen data — healthcare, housing on dark web @ $25,000
🧠 Intellectual Range — Draws connections between cybersecurity, genetics, philosophy, and political systems. Approaches security not as a technical exercise but as a discipline with human, societal, and structural dimensions.
🎯 Precise Under Pressure — Cited by national media during a live government breach crisis. Delivers structured, evidence-based analysis when others speculate. Calm is the strategy.
🔨 Builder Mentality — Most repositories are intentional open builds left accessible for the community to extend. Knowledge transfer matters more than attribution.
🌍 Mission-Driven — The infrastructure that ordinary South Africans depend on — healthcare portals, housing systems, government services — deserves to be genuinely secure against real, present threats. That is the work.
contact:
linkedin : https://www.linkedin.com/in/bongo-sijora/
github : https://github.com/b0n60
open_to:
- blue team tooling collaboration
- detection engineering projects
- south african threat intelligence sharing
- full-stack secure application development
- cybersecurity research and press engagement
- speaking on the ZA threat landscape