I Automated My Incident Response
I built a Python bot that monitors my Linux server, detects SSH brute force and web shell scanning, sends Slack alerts, and auto-blocks attackers via UFW.
I built a Python bot that monitors my Linux server, detects SSH brute force and web shell scanning, sends Slack alerts, and auto-blocks attackers via UFW.
After I documented my Linode server taking 4,000+ failed login attempts in 24 hours, the next obvious question was: what
A complete walkthrough of how I built and deployed a portfolio website on AWS S3 static hosting, CloudFront CDN, Route 53 custom domain, a serverless visitor counter with Lambda and DynamoDB, and automated CI/CD with GitHub Actions. No console clicking required.
The 7 best AI-powered cybersecurity tools for small businesses in 2026. Honest picks from a cloud security engineer. No enterprise jargon, no fear-mongering, just tools that actually work on a real budget.
I hadn’t published a single post yet. The server was brand new. Nobody had the link. And yet, less than 24 hours after going live, my Nginx error logs were full of automated bots hunting for exposed credentials. Here’s exactly what they were after and how I stopped them.