whoami
Qbitz. Viking dad. Homelab dweller. CTF grinder. Breaks things on purpose, builds AI agents to break them faster, then writes the defense to stop it all. Runs more Docker containers on Raspberry Pis than most people run apps on their phone.
About Me
Cybersecurity student + former IT operations professional + security researcher + tool builder. With a strong interest in network security, threat analysis, security engineering, incident response, and adversary simulation.
Before focusing fully on cybersecurity, I worked with operational IT environments administering Windows Server, Fortinet firewalls, networking, on-premises services, backups, and SMB infrastructure. That experience gave me a practical foundation in how real systems are deployed, maintained, broken, and repaired.
Outside university, I run a homelab built around Proxmox, Docker, Wazuh SIEM, segmented networks, firewall rules, zero-trust access, and 15+ monitored endpoints. I use it for detection engineering, log analysis, alert investigation, infrastructure experiments, automation, and security research.
My bachelor thesis, “From Headshots to Info Stealers: An Exploration Of Malware In Game Cheats”, investigates malware distribution through gaming-cheat ecosystems using static malware analysis, cryptographic hashes, VirusTotal intelligence, and threat-intelligence correlation.
I also build my own cybersecurity tools and interfaces using technologies including Python, Bash, PowerShell, Go, Git, and GitHub, increasingly incorporating AI-assisted and agentic development workflows.
I enjoy both sides of security: understanding how attackers think and building systems that make attacks harder to execute, easier to detect, and faster to investigate.
My long-term goal is a cybersecurity role where malware, networks, firewalls, endpoint security, monitoring, investigation, and hands-on technical problem solving are part of the everyday work.
What I work with
The homelab is where most ideas get battle-tested. I run Wazuh for SIEM monitoring, Pi-hole for DNS control, Twingate for ZTNA, Proxmox for virtualization, and a rotating stack of services in Docker. If a workflow can be scripted, it gets scripted.
- Languages: Python, Go, Bash, and whatever gets the job done.
- Platforms: Linux, Windows Server, Proxmox, Docker.
- Security tools: Wazuh, Suricata, Wireshark, Volatility, Burp Suite.
- Automation: CI/CD pipelines, infrastructure-as-code, custom agents.
Cybersecurity interests
- Active in CTF competitions and practical penetration testing training.
- Malware analysis and reverse engineering — static and dynamic triage.
- Threat hunting, detection engineering, and SIEM rule development.
- OSINT methodology and reconnaissance automation.
- AI-assisted security research and red-teaming workflows.
Projects and learning focus
Northforge is my personal security toolkit — a collection of web-based utilities for OSINT, binary triage, packet analysis, flashcards, and more. Every tool is built to solve a real problem I encountered during study or CTF play.