Skip to content
View sedat4ras's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report sedat4ras

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sedat4ras/README.md

Hi there, I'm Sed! πŸ‘‹

I'm Turkish, based in Melbourne πŸ‡¦πŸ‡Ί. Second-year ICT Security student, and I spent years as a progress-payment specialist, mechatronics technician, and QC data analyst before circling back to code.

That mixed background is my angle: I like building security automation shaped by a real domain and put behind a proper pipeline β€” not generic tooling.

I use this space to share what I'm building and how I'm learning. Reach out anytime.

πŸ“« sudo@sedataras.com β€” 🌐 sedataras.com

What I'm Focused On

πŸ›‘οΈ Security Automation & DevSecOps: Building CI/CD pipelines that catch problems early β€” SAST, SCA, secret scanning, container hardening β€” and shaping them into tools other teams can pick up (see ShieldScan).

πŸ€– AI in Security: Adding LLM layers where they earn their keep β€” scanner-output triage, honeypot deception, alert summarisation. Not AI for its own sake; AI as a force multiplier for security work.

🐍 Domain-Specific Tooling: Bringing prior-life expertise into code. My progress-payment project turns Turkish construction-payment know-how into a FastAPI system that keeps a human in the loop for anything ambiguous.

☁️ Cloud Security: AWS β€” running production honeypots on EC2 Spot (sentinel-vx), thinking about VPC design (secure-vpc-architecture), building on the AWS Cloud Practitioner foundation.

βš”οΈ Offensive Practice: Working through HTB and CPTS. This isn't the deliverable β€” it's the lens. You can't defend what you don't understand how to break.


Python Docker GitHub Actions AWS FastAPI Semgrep Ollama Kali Linux Burp Suite

Pinned Loading

  1. RuntimeReaper RuntimeReaper Public

    In-memory RASP (Runtime Application Self-Protection) Java agent that blocks RCE and unsafe-deserialization zero-days at runtime via Byte Buddy

    Java

  2. ShieldScan ShieldScan Public

    Python & AI based automated vulnerability scanner and reporter.

    Python 2

  3. dns-threat-intelligence-tool dns-threat-intelligence-tool Public

    Modular DNS threat hunting pipeline for PCAP analysis, featuring heuristic C2 beacon detection, Shannon entropy analysis, and real-time VirusTotal intelligence integration.

    Python 1

  4. hash-based-change-detector hash-based-change-detector Public

    "A lightweight File Integrity Monitor (FIM) written in Python. Uses SHA-256 hashing to detect unauthorized file modifications, creations, and deletions in real-time.

    Python 1

  5. sentinel-vx sentinel-vx Public

    AI-Deception SSH Honeypot with LLM Prompt Injection, real-time Telegram alerts, and OSINT enrichment

    Python 1

  6. progress-payment progress-payment Public

    Turns free-text field service slips into contract-priced progress payments. A language model proposes which contract item a line is; a deterministic engine decides what it costs.

    Python 1