Cybersecurity × AI × Systems

Building secure systems, hunting threats, and applying AI to cybersecurity

Cybersecurity student and aspiring security engineer exploring the intersection of threat detection, security engineering, automation, and applied AI — still early in the journey, deliberate about where it goes.

Cybersecurity AI Engineering Systems

About

I'm Nguyễn Trường Bảo, a Vietnamese student at Duy Tan University (Đại học Duy Tân) majoring in Cybersecurity / Information Security, expecting to graduate in about one year. I learn primarily through labs, home labs, technical docs, and building projects — not theory alone.

My path started in networking and systems, then deepened into cybersecurity: SOC concepts, threat hunting, web and Active Directory security, and security monitoring. I'm now expanding into AI engineering — not as a pure ML researcher, but to use AI to solve real security problems: triage, automation, analysis, and detection support.

Long-term directions I care about: Security Engineer, SOC / Detection Engineer, Threat Hunter, AI Security Engineer, Automotive Cybersecurity, and Security Automation.

Learn → Build → Break → Investigate → Automate → Improve

How I approach security work

What I'm focused on now

  • SOC operations, threat hunting, and detection thinking (Elastic, Sysmon, Windows logs)
  • Security automation and AI-assisted analysis (Wazuh pipelines, LLM workflows, Ollama)
  • Applied AI for cybersecurity — agents, RAG, prioritization — not foundation-model research
  • Automotive cybersecurity as a developing specialization
  • Hands-on practice: 30+ Hack The Box labs, PortSwigger Web Security Academy

Cybersecurity Journey

One coherent path — not a random stack of tools. Each stage builds on the previous.

  1. Networking

    TCP/IP, VLANs, routing, ACLs, DHCP/DNS, wireless — how packets and policies actually work.

  2. Systems

    Linux & Windows internals: permissions, processes, services, SSH, systemd, storage, Docker, VMs.

  3. Cybersecurity

    Offensive foundations + defensive mindset: web security, AD, vuln assessment, monitoring concepts.

  4. SOC / Threat Hunting

    Elastic Stack, Kibana, Sysmon, Windows Event Logs, IOC pivoting, MITRE ATT&CK, attack-chain reconstruction.

  5. Security Automation

    Scripting, correlation ideas, pipelines that reduce noise and speed up analyst workflows.

  6. AI Applications

    LLMs, agents, RAG, local models (Ollama) applied to triage, reporting, and analysis support.

  7. AI Security & Automotive

    Current direction — AI Security engineering + deepening automotive cybersecurity.

AI × Cybersecurity

AI is a second pillar — not a rebrand. The goal is applied AI that improves security workflows, not isolated academic ML.

Positioning: I am not presenting myself as a pure ML researcher. I am building toward Applied AI + Cybersecurity — using AI engineering to solve real security problems.

Where AI fits

  • LLM applications & security automation
  • AI agents for investigation support
  • RAG over security knowledge / intel
  • Alert prioritization & triage
  • AI-assisted malware / report analysis
  • Local LLMs (Ollama) for private workflows

Stack I'm exploring

Python LLM APIs LangChain MCP Ollama FastAPI RAG AI Agents

Expanding via hands-on projects and practical AI training In Progress

Why this intersection matters

SOC and hunting work generate volume: events, IOCs, process trees, intel reports. Applied AI can help prioritize signals, draft structured findings, and accelerate correlation — while humans remain accountable for decisions. That's the engineering problem I'm interested in, not "AI for its own sake."

Featured Projects

Prioritized by identity fit. Status is honest: implemented, in progress, or planned. GitHub links are placeholders until repos are public.

Tier 1 — Core identity

Tier 2 — Security foundation

Hands-on Lab

Home Lab

Virtualized + physical lab: networking, Linux, Docker, VMs, routers, Raspberry Pi, firewalls, VLANs, and security monitoring practice.

Docker VMware Linux
Lab notes →
Hands-on Lab

Network Security / VLAN / Firewall Lab

Inter-VLAN routing, STP/RSTP, EtherChannel, OSPF, NAT, ACL, QoS, SNMP — CCNA-level networking applied to security segmentation and troubleshooting.

VLAN ACL Firewall
Diagrams →
Learning

Web Security / WordPress Security

Hands-on study of auth issues, access control, injection, XSS, SSRF, file-related vulns, WordPress security, CVE research, and bug bounty methodology (PortSwigger Academy + labs).

Burp Suite OWASP WordPress
Write-ups →
Hands-on Lab

Active Directory / Windows Security Labs

Event logs, Sysmon, PowerShell logging, authentication events, lateral movement, credential attacks concepts (PsExec, SharpHound/BloodHound, DCSync concepts), always framed as lab learning.

Active Directory Sysmon Windows
AD notes →

Tier 3 — Supporting experiments

Learning

AI Agent & RAG Experiments

Small experiments with agents, RAG, MCP-style tooling, and local models — focused on security-relevant workflows (notes search, playbook drafts, triage helpers).

Agents RAG Ollama
Experiments →
Learning

Cloud / AWS Fundamentals

Foundational exposure to AWS concepts (e.g. EC2) for lab and security context — not claimed as production cloud architecture experience.

AWS EC2 Cloud
Notes →

Security Labs & Write-ups

Hands-on learning and investigation — not certificate collecting. 30+ Hack The Box labs (Linux, Windows, networking, AD, web, defensive) plus PortSwigger Web Security Academy practice. Filter notes below or open the full blog hub.

Skills

Practical exposure from labs and projects — not a claim of expert-level mastery in every tag.

Defensive / SOC

Wazuh Elastic Stack Kibana Sysmon Windows Event Logs Splunk (concepts) Microsoft Sentinel (concepts) SIEM Sigma MITRE ATT&CK Threat Hunting Threat Intelligence

Offensive / Testing

Burp Suite Nmap Gobuster FFUF John the Ripper Responder Kali Linux PortSwigger Academy Hack The Box Web vulns

Infrastructure / Systems

Linux Windows TCP/IP VLAN / Routing ACL / NAT SSH Bash systemd Docker iptables tcpdump AWS fundamentals

AD / Windows Security

Active Directory Authentication events Lateral movement concepts PowerShell logging SharpHound / BloodHound concepts Credential attack concepts

AI for Security

LLM applications AI Agents RAG LangChain MCP Ollama Python AI apps Security automation

Programming & Tooling

Python Bash PowerShell FastAPI Git / GitHub SQL HTML / CSS / JS

Automotive (developing)

Automotive security concepts Embedded Linux Network segmentation Firewall / logging Raspberry Pi labs

How I work

Hands-on labs Investigation notes Technical writing Troubleshooting Automation mindset

Experience & Training

Training and exposure contexts. Titles/dates use placeholders where not finalized — responsibilities are not exaggerated.

[ROLE]

Placeholder

LG Electronics R&D — Automotive cybersecurity context

[DATE]

Exposure to automotive cybersecurity training/work context: embedded Linux environments, firewall configuration, logging, network security practices relevant to vehicle-adjacent systems. Exact title and scope to be filled accurately.

[ROLE]

Placeholder

Fore-Z

[DATE]

Professional/training exposure (details to be completed without inventing responsibilities).

Cybersecurity Student

In Progress

Duy Tan University (Đại học Duy Tân) — Information Security / Cybersecurity

Expected graduation ~1 year

Formal study in cybersecurity with continuous hands-on labs: networking, systems, SOC/threat hunting, web & AD security, and growing AI-for-security projects.

AI Training Program

In Progress / Upcoming

Vin — practical AI training

[DATE]

Expanding AI engineering capabilities with a focus on applying AI to cybersecurity workflows rather than isolated academic ML.

Learning & Progress

Honest status only. No invented certifications. “In Progress” means studying — not certified.

HTB

Hack The Box — Hands-on Labs

Active practice

30+ labs across Linux, Windows, networking, Active Directory, web, and defensive security.

PSA

PortSwigger Web Security Academy

In Progress

Web vulnerability learning: auth, access control, injection, XSS, SSRF, and related topics.

Net

CCNA-level Networking Knowledge

Learning / Applied in labs

Practical networking foundation used in home lab and security segmentation work — not listed as an earned certification here.

SOC

SOC / Defensive Security & Threat Hunting

In Progress

Elastic, Sysmon, Windows logs, hunting methodology, ATT&CK, CTI concepts (strategic / operational / tactical).

AI

AI Engineering · Agents · Applied Security AI

In Progress

LLM apps, agents, RAG, automation for security use cases. Practical program at Vin — details TBD.

Auto

Automotive Cybersecurity

Developing specialization

Concepts, embedded Linux, segmentation, logging; interest in CAN, Automotive Ethernet, ISO 21434 / R155 — deeper study planned.

Contact

Open to internships, security engineering / SOC / threat hunting roles, AI-for-security collaboration, and lab discussions.

Get in touch

Send a message

Frontend demo only. Connect Formspree or your own backend when ready.