ML IoT Anomaly Detection Pipeline
Capstone. Isolation Forest trained on the IoT-23 dataset, served via a Flask API on a Raspberry Pi 4B, live predictions feeding an Elastic and Kibana dashboard for real-time triage.
View repoBeyond the two case studies
A personal project with a genuinely hard problem in it, the academic work three years of the degree produced, and the tooling that sits underneath all of it.
Personal project
A private tracker I built for my own training, recovery, supplements and lab results. Doses and sessions go in, and the app models how much of each supplement or prescribed medication is still active from its published half-life, projects that a week forward, and plots it against my body and lab trends. The part that actually interested me is the pharmacokinetics: every entry decays on its own exponential curve, absorption and elimination run at different rates, and overlapping doses have to sum correctly across weeks. I built it local-first on purpose: reminders are scheduled on the device, cloud sync is optional, and the whole record exports as JSON I actually own.
Capstone. Isolation Forest trained on the IoT-23 dataset, served via a Flask API on a Raspberry Pi 4B, live predictions feeding an Elastic and Kibana dashboard for real-time triage.
View repoFull examination of forensic disk images: hash-verified integrity, artefact recovery and correlation with Autopsy, FTK Imager and Eric Zimmerman tools, counter-forensics identified (JPEG/ZIP polyglot, AES archives). Delivered as a court-style expert report.
Brave, Firefox and IceCat compared across Kali Linux and macOS, replicating identical activity on each so the artefacts lined up: cookie and history databases read in DB Browser for SQLite, plus cache, local and session storage, IndexedDB and tracker blocking, closing on a per-browser deployment recommendation. Scored 75/75, with 20/20 on the presentation.
Contributed to a group security assessment of a healthcare provider holding 800,000 patient records and 2 million administrative records. Each policy gap worked through its risks, threats, countermeasures and exposure under the Privacy Act 1988, ending in four action areas answered with MFA, password rotation, RBAC and VPN restriction, plus a staff training programme designed against published awareness research.
Incident response plan for a simulated APT38 intrusion against a financial institution, mapped to the cyber kill chain and MITRE ATT&CK, structured on the ACSC template with NIST and SANS lifecycle stages.
Spam, network intrusion and DDoS detection classifiers in Python (scikit-learn, TensorFlow, PyTorch), evaluated on accuracy, precision and recall, and tested against adversarial ML evasion.
Supervised classification on a 35,000-record lending dataset: EDA, engineered temporal features, a deliberate missing-data strategy and a held-out 15,000-prediction submission, including a date-format bug caught before it silently corrupted half the test set.
Team project at Universiti Sains Malaysia: survey data cleaned and modelled in JMP and R, then built into a Tableau dashboard and presented to the cohort at the close of the school.
SIEM (Elastic & Kibana) · log analysis · incident response · digital forensics · MITRE ATT&CK · AWS cloud security · Wireshark
Python (scikit-learn, TensorFlow, PyTorch) · JavaScript & TypeScript · Next.js · Supabase (Postgres, RLS) · offline-first PWAs · Git & CI
pandas · feature engineering · JMP · R & RStudio · Tableau · Power BI · model evaluation and adversarial testing
Anthropic Claude and Claude Code · agent skills and MCP connectors · prompt and context design · AI-assisted development, review and documentation
Tor · PGP and GnuPG key management in Kleopatra · VPNs · explored cryptocurrency and blockchain, including running nodes locally
Diploma of Information Technology, Deakin College (2023)
Hiring in Sydney?
Graduate cyber security or sales engineering.