Skip to content
View Hugh-Kumbi's full-sized avatar

Block or report Hugh-Kumbi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Hugh-Kumbi/README.md

Hi, I'm Hugh Chanetsa πŸ‘‹

πŸ“ Hiroshima, Japan | πŸ›‘οΈ Cybersecurity Professional | 🎯 SOC β€’ CTI β€’ Vulnerability Management | πŸš€ Security Researcher

Python Linux SQL PowerShell Windows Server Active Directory OpenVAS Nessus Splunk Wazuh MITRE ATT&CK OSINT Wireshark Docker VMware Threat Intelligence: STIX | MISP | ATT&CK

Building practical cybersecurity capabilities through hands-on labs, cyber threat intelligence, vulnerability management, and security automation to help organizations detect, investigate, and defend against evolving threats.

About Me

I'm a multidisciplinary cybersecurity professional combining technical expertise with a unique educational background spanning computer science, business, and social sciences. Based in Japan, I'm actively seeking cybersecurity opportunities while building Mei Vault Systems - a security-focused startup project where I'm developing practical solutions and expanding my technical portfolio.

Education:

  • πŸŽ“ B.S. Computer Science (Software Engineering) - University of the People
  • πŸ“Š B.Com (Hons) Management Studies - University of Cape Town
  • 🌐 B.A. Social Sciences (IR, Economic History, Industrial Sociology) - University of Cape Town

Current Focus

  • πŸ” Application Development Security & Secure Coding Practices
  • 🌐 Network Security & System Administration
  • πŸ€– Python Automation for Security Operations
  • πŸ“Š Security Information & Event Management (SIEM)
  • 🎯 Risk Assessment & Mitigation Strategies
  • πŸ›‘οΈ Detection Engineering & Threat Hunting

Certifications

Featured Projects

πŸ›‘οΈ Cybersecurity Portfolio

Comprehensive portfolio demonstrating security frameworks, incident response, and hands-on tools:

  • NIST Cybersecurity Framework implementation
  • Security audits and risk assessments
  • Linux & SQL security operations
  • Threat detection with Wireshark, tcpdump, Suricata
  • SIEM implementations (Splunk, Chronicle)
  • Python security automation scripts

Tech: Python Linux SQL Wireshark Suricata Splunk NIST Framework


Professional end-to-end vulnerability assessment framework demonstrating enterprise security operations.

A comprehensive vulnerability management lifecycle project showcasing:

  • Multi-scanner vulnerability assessment (OpenVAS, Nessus Essentials Plus)
  • Risk-based prioritization using CVSS + business impact analysis
  • Compliance mapping across NIST 800-53, ISO 27001, CIS Controls, PCI-DSS, HIPAA
  • Python automation for scan orchestration and reporting
  • Flask-based real-time metrics dashboard
  • SIEM integration (Wazuh) with correlation rules
  • 415+ vulnerable services across isolated lab environment (Metasploitable2/3, DVWA, OWASP Juice Shop)
  • Professional executive and technical reporting

Tech: OpenVAS Nessus Python Flask Wazuh Docker VMware NIST ISO 27001 Jupyter

Key Achievement: Built enterprise-grade vulnerability management lab demonstrating 225+ CVE assessments with automated remediation workflows and multi-framework compliance validation.


Comprehensive Cyber Threat Intelligence (CTI) investigation into a multi-domain recruitment fraud campaign using structured OSINT methodologies and industry-standard intelligence frameworks.

This end-to-end investigation demonstrates professional CTI tradecraft through evidence-based intelligence collection, infrastructure analysis, behavioural correlation, and defensive reporting.

Highlights include:

  • Intelligence Lifecycle applied from collection through dissemination
  • Multi-domain infrastructure correlation across five operational domains
  • Passive DNS, WHOIS, Certificate Transparency, and SSL analysis
  • Technology stack fingerprinting and cloud infrastructure analysis
  • MITRE ATT&CK mapping and ATT&CK Navigator layer
  • Diamond Model and Attack Lifecycle analysis
  • Detection engineering with SIEM, Sigma, Splunk SPL, and Microsoft Sentinel (KQL) examples
  • Intelligence Requirements, Intelligence Gaps, and Confidence Assessments
  • IOC development, STIX 2.1 and MISP intelligence exports
  • Mermaid attack graph and executive intelligence reporting

Tech: CTI OSINT MITRE ATT&CK ATT&CK Navigator STIX 2.1 MISP Passive DNS WHOIS Certificate Transparency Sigma Splunk KQL

Key Achievement: Produced a complete Cyber Threat Intelligence investigation including structured OSINT collection, MITRE ATT&CK mapping, ATT&CK Navigator, STIX/MISP intelligence exports, detection engineering recommendations, and executive reporting for a real-world multi-domain recruitment fraud campaign.


Enterprise-grade AD environment showcasing Windows Server administration and security:

  • Windows Server 2025 deployment and configuration
  • Active Directory Domain Services (AD DS) setup
  • Group Policy Objects (GPO) implementation
  • User management and security policy enforcement
  • PowerShell automation scripts

Tech: Windows Server 2025 Active Directory PowerShell Group Policy DNS DHCP


Real-world security automation demonstrating Python's power in cybersecurity operations:

  • Login process automation and analysis
  • Pattern detection using regex
  • Security log parsing and investigation
  • Automated threat detection workflows

Tech: Python Regex Security Automation Log Analysis


Portfolio hub featuring documentation, academic projects, and professional development work focusing on DevSecOps and secure coding practices.

Technical Skills

Cyber Threat Intelligence (CTI) & OSINT

  • Intelligence Lifecycle & Structured Analytic Techniques
  • Open Source Intelligence (OSINT) Collection & Analysis
  • Threat Actor & Infrastructure Profiling
  • Passive DNS, WHOIS & Certificate Transparency Analysis
  • MITRE ATT&CK & ATT&CK Navigator
  • Diamond Model & Attack Graph Analysis
  • STIX 2.1 & MISP Threat Intelligence
  • Indicators of Compromise (IOC) Development
  • Threat Hunting & Intelligence Reporting

Detection Engineering & Security Operations

  • Threat Detection & Incident Response
  • SIEM Engineering (Splunk, Chronicle, Wazuh)
  • Detection Logic Development
  • Sigma Rule Development
  • Microsoft Sentinel (KQL)
  • Splunk SPL
  • Network Traffic Analysis (Wireshark, tcpdump)
  • Intrusion Detection Systems (Suricata)

Vulnerability Management

  • Vulnerability Scanning (OpenVAS, Nessus Essentials Plus, Nuclei)
  • Risk Assessment & Prioritization (CVSS, Business Impact Analysis)
  • Patch Management & Remediation Validation
  • False Positive Analysis & Multi-Scanner Correlation
  • Compliance Mapping (NIST 800-53, ISO 27001, CIS Controls, PCI DSS, HIPAA)

Infrastructure & System Administration

  • Windows Server Administration
  • Active Directory & Group Policy
  • Linux System Administration
  • TCP/IP, DNS & DHCP
  • Network Security & Monitoring
  • VMware Workstation
  • Enterprise Lab Design & Isolation

Development & Security Automation

  • Python (Security Automation & Analysis)
  • PowerShell
  • SQL
  • Flask
  • Git & Version Control
  • Docker
  • Secure Software Development Lifecycle (SSDLC)
  • Jupyter Notebooks

πŸ“Š Portfolio Impact

Highlights

  • πŸ” Completed an end-to-end Cyber Threat Intelligence investigation into a multi-domain recruitment fraud campaign
  • πŸ“‘ Produced STIX 2.1 and MISP intelligence exports for operational sharing
  • 🎯 Developed SIEM, Sigma, Splunk, and Microsoft Sentinel detection opportunities
  • πŸ›‘οΈ Built enterprise vulnerability management and Active Directory lab environments
  • πŸ“Š Developed security automation using Python, PowerShell, and Flask
  • 🧠 Applied the Intelligence Lifecycle, MITRE ATT&CK, Diamond Model, and ATT&CK Navigator
  • πŸ… Earned industry certifications including ISCΒ² CC and Google Cybersecurity Professional Certificate

What Drives Me

I'm passionate about staying ahead of emerging cyber threats and helping organizations build resilient security postures. My unique combination of technical skills, business acumen, and understanding of organizational dynamics enables me to approach cybersecurity challenges from multiple angles.

Core Values:

  • βœ… Ethical security practices and responsible disclosure
  • 🎯 Proactive threat hunting over reactive responses
  • πŸ”„ Continuous learning in an evolving threat landscape
  • 🀝 Knowledge sharing and community contribution

Connect With Me

LinkedIn Twitter Instagram Email Website

πŸ“„ View My Resume


πŸ’‘ Open to collaboration on cybersecurity projects and security research initiatives

🌏 Currently based in Hiroshima, Japan (UTC +9)

Pinned Loading

  1. Operation-Phantom-Store Operation-Phantom-Store Public template

    Evidence-based Cyber Threat Intelligence (CTI) investigation of a multi-domain recruitment fraud campaign using OSINT, MITRE ATT&CK, STIX, MISP, and ATT&CK Navigator.

    YARA

  2. Vulnerability-Management-Portfolio Vulnerability-Management-Portfolio Public

    A full end-to-end vulnerability management workflow demonstrating scanning, analysis, prioritization, remediation, and validation using industry-standard tools and intentionally vulnerable systems.

    Python

  3. Cybersecurity-Portfolio Cybersecurity-Portfolio Public

    I built a rigorous cybersecurity project portfolio for simulated clients, covering NIST frameworks, audits, Linux, SQL, assets, threats, vulnerabilities, detection, incident response, escalation, W…

    Jupyter Notebook 5

  4. Hugh-Kumbi-Active-Directory-Lab Hugh-Kumbi-Active-Directory-Lab Public

    This repository contains detailed documentation of my Active Directory (AD) home lab setup. It covers the entire process, including installing Windows Server 2025, configuring AD, creating users, a…

    PowerShell 13 6

  5. Python-Driven-Cybersecurity-Case-Study Python-Driven-Cybersecurity-Case-Study Public

    In this case study, I utilized Python to streamline the login process, perform an in-depth analysis of login data, and identify patterns using regular expressions. The project highlights how Python…

    Jupyter Notebook 1