Skip to content
View AurelioAvila's full-sized avatar

Block or report AurelioAvila

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AurelioAvila/README.md

Aurelio Avila

Security operations, detection engineering and Windows software.

I build defensive tools and practical applications, with a focus on clear evidence, useful diagnostics and understandable controls. My work spans incident investigation, reproducible security labs and products for creators, digital agencies and Windows users.

Explore products · Security projects · Skills and tools · Get in touch


Products

Verified Windows releases: PC Tweaker 1.9.0, Redaxa 0.3.3 and Redexa Social 1.9.3 carry timestamped Certum signatures identifying Aurelio Avila as publisher. See the signing status and verification guide, including the unsigned PC Tweaker Uninstaller 0.8.2 exception.

Glarion

Website security monitoring and client-ready reporting for digital agencies. Glarion identifies meaningful changes, turns technical findings into clear deliverables and requires current proof of domain control before active scans.

CI Rust

Product site and current plans

Check a website without an account · View the sample report · Read the security model

PC Tweaker

Windows performance, gaming, privacy and maintenance tools with reversible tweaks and recovery features. Review each action and its requirements before applying system changes.

GitHub downloads Release

Product site · Microsoft Store · Softpedia · MajorGeeks

Redaxa

Catches secrets, credentials and personal data in text before it is pasted into ChatGPT, Claude, Gemini or Copilot. Scanned on our backend, never sent to an AI provider — details in the privacy section.

Release

Desktop app, browser extension and web version

Try the web app · Download for Windows

Redexa Social

Local-first creator analytics for YouTube, Instagram, TikTok and X, subject to platform permissions and API availability. Analytics history stays on your device. Account connections and optional paid features use the services described in the privacy policy.

Release

Product site · Download for Windows

CertSprint

Practice tests for IT certification exam prep (Security+, CySA+ and other vendor tracks), built to mirror real exam format and scoring.


Security engineering

Explore detection tools, investigation walkthroughs and documented labs. Repository READMEs explain the available evidence, sample data, test commands and limitations so you can evaluate each project directly.

Project What it does
detection-engineering-rules YARA and Sigma rules, each checked against true and false positive cases. Sigma is compiled to real Splunk SPL with pySigma rather than validated as YAML.
network-traffic-analysis Scapy PCAP analyser for port scans, C2 beaconing and floods. A statistical baseline catches slow floods that fixed thresholds structurally cannot, with a side-by-side demo showing the difference.
malware-triage-hash Hash reputation joined to behavioural scoring, so an unknown sample is not read as a clean one. Ships a Sentinel KQL hunt.
ransomware-dfir-timeline Process, Prefetch, Registry and filesystem artifacts correlated into a single timeline, from the opened attachment to mass encryption, with root cause and detection gaps.
phishing-email-analysis Parses raw .eml, extracts headers, URLs and attachment hashes, flags typosquatting and urgency patterns, enriches through VirusTotal.
splunk-brute-force-detection SPL detections for brute force and password spraying in Windows Security logs, with threshold tuning notes and a triage playbook.
soc-home-lab Wazuh and OpenSearch lab: custom rules, agent deployment, ingestion validation, and the full path from alert to incident report.
dma-guide Reference on DMA attack mechanics and the controls that stop them, from IOMMU and VT-d to Kernel DMA Protection.

The incident and detection projects include MITRE ATT&CK context where applicable.


Background

SOC analyst, currently Tier 1, handling alert triage, log correlation and detection tuning across Microsoft Sentinel, Splunk and Wazuh.

Certifications and course credentials

Security+ CySA+ SC-200 BTL1 Trinity ISE III Anthropic Introduction to MCP Anthropic AI Capabilities and Limitations Anthropic AI Fluency for Builders

Skills and tools

Area Skills, platforms and tools
Security operations Alert triage · Incident investigation · Log correlation · Threat hunting · Detection tuning · Escalation and incident reporting · SOAR playbooks
SIEM and detection Microsoft Sentinel · KQL · Splunk · SPL · Wazuh · OpenSearch · Sigma · YARA · pySigma · MITRE ATT&CK
DFIR and malware analysis Windows event analysis · Process, Prefetch, Registry and filesystem artifacts · Timeline reconstruction · Hash reputation · Behavioural triage · VirusTotal API · Sandbox evidence
Network and email security Wireshark · Scapy · PCAP analysis · Traffic baselining · Port-scan, beaconing and flood detection · Email header analysis · IOC extraction and enrichment
Application and AI security Nuclei · SSRF protection · Domain ownership verification · Secret and PII detection · Data-loss prevention · LLM security · MCP fundamentals
Software development Rust · TypeScript · Python · JavaScript · SQL · React · Tauri · FastAPI · Axum · PostgreSQL · REST APIs
Platforms and identity Windows 10/11 · Linux and Ubuntu · Microsoft Azure · Microsoft Entra ID · Microsoft Store · winget
Engineering workflow Git · GitHub · GitHub Actions · CI/CD · Automated testing · Visual Studio Code · Security scanning · Release automation
Threat-intelligence frameworks STIX/TAXII · Pyramid of Pain · IOC lifecycle · Behaviour-to-technique mapping

The technologies above are reflected in shipped products, reproducible security labs or day-to-day security operations.

Languages — Italian (native), English (C1), French (B2), Spanish (B1)


Contact

aurelio_11@outlook.it · Amsterdam

Happy to talk about any of the products above, and open to security engineering work.

Pinned Loading

  1. network-traffic-analysis network-traffic-analysis Public

    Python and Scapy PCAP analyzer with port-scan, C2, flood and statistical anomaly detection, MITRE ATT&CK mapping and SOC reports.

    Python 4

  2. pc-tweaker-app pc-tweaker-app Public

    Windows tuning for performance, gaming and privacy, with hardware monitoring and restore tools for supported settings. Built with Rust and Tauri.

    TypeScript 20

  3. redexa-social redexa-social Public

    Redexa Social — private, local-first creator analytics for YouTube, Instagram, TikTok and X on Windows.

    Python 7

  4. redaxa redaxa Public

    Redaxa (formerly PromptShield): AI privacy and DLP protection that detects and redacts secrets, credentials and PII before they reach ChatGPT, Claude, Gemini or Copilot.

    TypeScript 1

  5. detection-engineering-rules detection-engineering-rules Public

    YARA and Sigma detection rules, written and unit-tested against real sample sets and synthetic log events, with MITRE ATT&CK mapping and a pySigma-based test harness.

    Python 1

  6. glarion glarion Public

    Website security monitoring and client-ready reporting for digital agencies, with ownership-gated scanning and white-label reports.

    Rust 1