Where AI fits
- LLM applications & security automation
- AI agents for investigation support
- RAG over security knowledge / intel
- Alert prioritization & triage
- AI-assisted malware / report analysis
- Local LLMs (Ollama) for private workflows
Cybersecurity × AI × Systems
Cybersecurity student and aspiring security engineer exploring the intersection of threat detection, security engineering, automation, and applied AI — still early in the journey, deliberate about where it goes.
I'm Nguyễn Trường Bảo, a Vietnamese student at Duy Tan University (Đại học Duy Tân) majoring in Cybersecurity / Information Security, expecting to graduate in about one year. I learn primarily through labs, home labs, technical docs, and building projects — not theory alone.
My path started in networking and systems, then deepened into cybersecurity: SOC concepts, threat hunting, web and Active Directory security, and security monitoring. I'm now expanding into AI engineering — not as a pure ML researcher, but to use AI to solve real security problems: triage, automation, analysis, and detection support.
Long-term directions I care about: Security Engineer, SOC / Detection Engineer, Threat Hunter, AI Security Engineer, Automotive Cybersecurity, and Security Automation.
Learn → Build → Break → Investigate → Automate → Improve
One coherent path — not a random stack of tools. Each stage builds on the previous.
TCP/IP, VLANs, routing, ACLs, DHCP/DNS, wireless — how packets and policies actually work.
Linux & Windows internals: permissions, processes, services, SSH, systemd, storage, Docker, VMs.
Offensive foundations + defensive mindset: web security, AD, vuln assessment, monitoring concepts.
Elastic Stack, Kibana, Sysmon, Windows Event Logs, IOC pivoting, MITRE ATT&CK, attack-chain reconstruction.
Scripting, correlation ideas, pipelines that reduce noise and speed up analyst workflows.
LLMs, agents, RAG, local models (Ollama) applied to triage, reporting, and analysis support.
Current direction — AI Security engineering + deepening automotive cybersecurity.
AI is a second pillar — not a rebrand. The goal is applied AI that improves security workflows, not isolated academic ML.
Positioning: I am not presenting myself as a pure ML researcher. I am building toward Applied AI + Cybersecurity — using AI engineering to solve real security problems.
Expanding via hands-on projects and practical AI training In Progress
SOC and hunting work generate volume: events, IOCs, process trees, intel reports. Applied AI can help prioritize signals, draft structured findings, and accelerate correlation — while humans remain accountable for decisions. That's the engineering problem I'm interested in, not "AI for its own sake."
Prioritized by identity fit. Status is honest: implemented, in progress, or planned. GitHub links are placeholders until repos are public.
Problem: Analysts need structured, explainable analysis of samples — static signals, behavior, IOCs, and ATT&CK context — not raw tool dumps.
Security platform concept combining static/dynamic analysis with AI-assisted classification, IOC extraction, MITRE ATT&CK mapping, and analyst-friendly reports.
Sample → Static → Features → Dynamic/Sandbox → AI analysis → Classification → ATT&CK → IOCs → Report
Problem: Alert fatigue — volume of SIEM events makes prioritization hard for early analysts.
Pipeline from Wazuh (or similar) security events through correlation and AI-assisted analysis to prioritized alerts, exposed via FastAPI with optional Telegram notifications.
Wazuh → Events → Correlation → AI analysis → Priority → FastAPI → Notify (Telegram)
Problem: Reconstruct a multi-stage attack from telemetry and intel without a single “smoking gun” alert.
Hands-on training investigation of a fictional threat actor Stuxbot: phishing → OneNote → scripted payload → PowerShell → C2 → AD recon (SharpHound) → credential activity → PsExec lateral movement. Presented as lab / training, not professional employment.
Phishing → invoice.one → OneNote → cmd/bat → PS → Pastebin → C2/Ngrok → SharpHound → PsExec
Problem: Vehicle-adjacent environments need segmented networks, logging, and hardened Linux/embedded stacks.
Hands-on exposure to automotive security concepts in Linux-based environments (e.g. WebOS-related stacks), firewalling, logging (ulogd2 / iptables), Raspberry Pi labs, VLANs, and segmentation. Interested in expanding into CAN, Automotive Ethernet, ECU security, UNECE R155 / ISO 21434 — not claimed as advanced expertise yet.
Notes / lab docs →Virtualized + physical lab: networking, Linux, Docker, VMs, routers, Raspberry Pi, firewalls, VLANs, and security monitoring practice.
Lab notes →Inter-VLAN routing, STP/RSTP, EtherChannel, OSPF, NAT, ACL, QoS, SNMP — CCNA-level networking applied to security segmentation and troubleshooting.
Diagrams →Hands-on study of auth issues, access control, injection, XSS, SSRF, file-related vulns, WordPress security, CVE research, and bug bounty methodology (PortSwigger Academy + labs).
Write-ups →Event logs, Sysmon, PowerShell logging, authentication events, lateral movement, credential attacks concepts (PsExec, SharpHound/BloodHound, DCSync concepts), always framed as lab learning.
AD notes →Small experiments with agents, RAG, MCP-style tooling, and local models — focused on security-relevant workflows (notes search, playbook drafts, triage helpers).
Experiments →Foundational exposure to AWS concepts (e.g. EC2) for lab and security context — not claimed as production cloud architecture experience.
Notes →Hands-on learning and investigation — not certificate collecting. 30+ Hack The Box labs (Linux, Windows, networking, AD, web, defensive) plus PortSwigger Web Security Academy practice. Filter notes below or open the full blog hub.
No posts in this category yet.
Practical exposure from labs and projects — not a claim of expert-level mastery in every tag.
Training and exposure contexts. Titles/dates use placeholders where not finalized — responsibilities are not exaggerated.
LG Electronics R&D — Automotive cybersecurity context
[DATE]
Exposure to automotive cybersecurity training/work context: embedded Linux environments, firewall configuration, logging, network security practices relevant to vehicle-adjacent systems. Exact title and scope to be filled accurately.
Fore-Z
[DATE]
Professional/training exposure (details to be completed without inventing responsibilities).
Duy Tan University (Đại học Duy Tân) — Information Security / Cybersecurity
Expected graduation ~1 year
Formal study in cybersecurity with continuous hands-on labs: networking, systems, SOC/threat hunting, web & AD security, and growing AI-for-security projects.
Vin — practical AI training
[DATE]
Expanding AI engineering capabilities with a focus on applying AI to cybersecurity workflows rather than isolated academic ML.
Honest status only. No invented certifications. “In Progress” means studying — not certified.
30+ labs across Linux, Windows, networking, Active Directory, web, and defensive security.
Web vulnerability learning: auth, access control, injection, XSS, SSRF, and related topics.
Practical networking foundation used in home lab and security segmentation work — not listed as an earned certification here.
Elastic, Sysmon, Windows logs, hunting methodology, ATT&CK, CTI concepts (strategic / operational / tactical).
LLM apps, agents, RAG, automation for security use cases. Practical program at Vin — details TBD.
Concepts, embedded Linux, segmentation, logging; interest in CAN, Automotive Ethernet, ISO 21434 / R155 — deeper study planned.
Open to internships, security engineering / SOC / threat hunting roles, AI-for-security collaboration, and lab discussions.