Skip to content
View z4ng1ew's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report z4ng1ew

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
z4ng1ew/README.md

visitors

Typing SVG

DevSecOps β€’ InfoSec β€’ Software Engineer


πŸš€ About Me

  • 🎯 DevSecOps engineer with a background in full-stack development, information security, and law.
  • πŸ’Ό Lead Information Security Specialist
  • πŸ” Specializing in secure development, automation, CI/CD, and Linux hardening.
  • πŸ“¦ Tech stack: Docker, Kubernetes, GitLab CI/CD, Trivy, Bandit, Fail2Ban, MaxPatrol SIEM
  • πŸŽ“ Building pet projects and competing in CTFs

🧰 Skills & Technologies


πŸ”— Profiles

White-hat hacker platform (Nickname: C0deBre4ker)

  1. Root-me: https://www.root-me.org/C0deBre4ker?lang=fr#ab47c9ae0213499c3977225d6757616e
  2. GitLab: https://gitlab.com/z4ng1ew
  3. DockerHub: https://hub.docker.com/u/zangievmovsar
  4. Kaggle (ML/AI research): https://www.kaggle.com/nyzprocent
  5. Saturn Cloud: https://app.community.saturnenterprise.io/dash/o/Knyaz-Procent
  6. Hugging Face: https://huggingface.co/V1ncy

πŸ› οΈ Projects

Demonstrates deploying an nginx application in Kubernetes using Helm charts.

Jenkins job configuration, Git integration, and pipeline creation for DevOps workflows.

Educational Flask application featuring Trivy, TruffleHog, and Bandit for secure development and CI/CD scanning.

πŸ›‘οΈ OWASP-ZAP-Scan

Automated security testing of a Flask web application using OWASP ZAP in headless mode with HTML reporting, integrated into DevSecOps practices.

πŸ”’ SecureOps

Microservices in Docker, CI/CD pipelines on GitHub Actions, protection via UFW, Fail2Ban, HTTPS, and automated vulnerability scanning.

Java fuzz testing, Maven builds, BOM generation, and automated SCA analysis using Dependency-Track. Docker Compose setup makes the project ready for DevSecOps. An ideal lab for learning secure development and detecting vulnerabilities at early stages.

🐳 Docker-Nginx

Creating and configuring a Docker container with nginx and a FastCGI-based mini-server, including security analysis using Dockle and multi-container setup with Docker Compose.

Practical fuzz testing using AFL++ for discovering vulnerabilities in C programs.

Bash utilities written in C from scratch. Analogs of grep, cat, and others, with test coverage, CI, and Valgrind analysis.

πŸ”£ String.h

Custom implementation of the string.h library in C, including extended formatting functions (sprintf, sscanf) and additional string manipulation utilities. This project deepens understanding of strings, pointers, formatting, and POSIX standards.


πŸ“Š GitHub Stats

GitHub Streak Profile Details Repos per Language Most Commit Language Stats Productive Time

Pinned Loading

  1. Trivy-Flask-App-With-Bandit-TruffleHog Trivy-Flask-App-With-Bandit-TruffleHog Public

    Flask app with Trivy and Bandit integrated in a CI/CD pipeline for automated security scanning and vulnerability detection.

    Python 1

  2. Advanced-Linux-Networking-Static-Routing-Firewalling-Secure-Tunnelling-with-iptables-and-SSH Advanced-Linux-Networking-Static-Routing-Firewalling-Secure-Tunnelling-with-iptables-and-SSH Public

    A hands-on project demonstrating core Linux networking concepts, including static routing, firewalling with iptables, DHCP configuration, NAT, and secure SSH tunneling on virtual machines.

  3. Docker_prj Docker_prj Public

    Dockerfile