Cybersecurity Engineer, MSS Associate at EXEO

Is this alert nothing, or the start of something.

I work in detection and response: SIEM/SOAR engineering, threat intelligence, and closing the gaps that let something in before it becomes a headline. This is a working notebook of that work, plus the background behind it.

About

I got into this field the practical way: fixing infrastructure first, watching it get attacked second. That order still shapes how I work. Before I trust a dashboard, I want to know what's actually generating the data behind it.

Day to day, that means log analysis, tuning detection rules so they catch real threats instead of drowning in noise, and the slower, less exciting work of closing the gaps that let something in before it becomes a headline. None of it is dramatic. Most good security work isn't.

I'm currently a Managed Security Services Associate at EXEO, working across SIEM and SOAR engineering, threat intelligence, and cloud and container security for a multi-tenant client base. I'm based in Lebanon, and I'm finishing a Master's in Cybersecurity alongside the day-to-day work.

Experience

EXEO

Managed Security Services Associate / Cybersecurity Engineer

  • Design and tune SIEM/SOAR detection content across Wazuh, Microsoft Sentinel, and FortiSOAR for a multi-tenant MSSP environment.
  • Built out a cyber threat intelligence workflow around OpenCTI, feeding indicators into detection and enrichment.
  • Cloud and container security work spanning AWS, Azure, and Kubernetes (including AKS), using Sysdig Secure for runtime visibility and Wazuh for cluster and audit-log monitoring.
  • Built a Python-based log pipeline on Azure (Timer Trigger Function, Key Vault-backed credentials via Managed Identity) that pulls Cloudflare audit logs and forwards them into Azure Log Analytics for Wazuh to ingest and alert on, and wrote the documentation for it for audit and compliance approval.
  • Email security engineering: SPF/DKIM/DMARC configuration and mail flow troubleshooting across client domains.
  • Active Directory hardening (least-privilege reviews, privileged event alerting) and ISO 27001/27002 alignment work.
  • Cloudflare administration for client zones: WAF and custom rule tuning, Workers, Tunnels, and DNS, including post-incident log analysis to confirm rules were actually firing as intended.
Systems Integrator

Systems Integrator

  • Managed and maintained an estate of 1,000+ devices, handling deployment, patching, and day-to-day systems support.
  • Worked across the ManageEngine suite: Endpoint Central, Patch Manager Plus, Vulnerability Manager Plus, ADAudit Plus, and ServiceDesk Plus.
IT Support & SOC Agent

IT Support & SOC Agent

  • Entry point into the field: general IT support alongside first exposure to SOC monitoring and alert triage.

Skills

Detection & response

WazuhMicrosoft Sentinel FortiSOARLog360 CrowdStrikeBitdefender OpenCTI

Cloud & container security

AWSAzure Kubernetes / AKSSysdig Secure Azure Key VaultAzure Log Analytics Azure Functions

Scripting & automation

PythonBash Cloudflare APIWazuh Azure wodle

Edge & perimeter security

Cloudflare WAFCloudflare Workers Cloudflare TunnelsDNS

Identity & email security

Active DirectorySPF / DKIM / DMARC FortiMailMimecast

Governance & compliance

ISO 27001ISO 27002

Endpoint & systems management

Endpoint CentralPatch Manager Plus Vulnerability Manager PlusADAudit Plus ServiceDesk Plus

Networking

Routing & switching (CCNA level)

Certifications & education

Certifications

  • ISC2 Certified in Cybersecurity
  • EC-Council Ethical Hacking Essentials
  • Cisco CCNA
  • Bitdefender Technical Solutions Professional
  • CompTIA CySA+in progress

Education

  • MSc, Cybersecurity
    Lebanese American University
    in progress
  • BSc
    Antonine University
    2019–2025

Writeups

September 2026 · Project notes

Connecting Cloudflare Security Insights to Wazuh: building my own webhook bridge

Every security tool speaks its own language, and getting them to talk to each other is often the hardest part of running a home lab or a small security stack. That was exactly the challenge I ran into with Cloudflare and Wazuh.

The problem

Cloudflare has a great feature called Security Insights. It periodically scans your domains and flags risky configurations, things like DNS records pointing to servers that no longer exist, or origin IPs that are accidentally exposed to the internet. Left unnoticed, issues like these are exactly what attackers look for.

The catch is that Cloudflare has no built-in way to send these alerts into Wazuh, the open-source security monitoring platform I use to keep an eye on my infrastructure. Cloudflare can send a generic webhook notification, but there's no ready-made connector on the Wazuh side to receive and understand it. So I decided to build the bridge myself.

The idea

The plan was simple in concept: set up a small, lightweight service that can receive Cloudflare's webhook notifications, make sure it only accepts requests genuinely coming from Cloudflare, save each alert in a clean structured format, and have Wazuh watch that file and turn the alerts into proper security events on my dashboard.

The trickiest part wasn't the logic, it was making sure this little service could safely receive traffic from the internet without opening up my server to it directly. For that, I used a Cloudflare Tunnel, which lets Cloudflare securely forward traffic to a service running on my server without me ever having to open a firewall port to the outside world.

How it works, end to end

Here's the journey an alert takes today: Cloudflare's Security Insights feature detects something worth flagging, say, a DNS record pointing to nothing. Cloudflare sends a notification out to a secure address, protected by a private key only my server and Cloudflare know. That notification travels through the Cloudflare Tunnel, straight to the small listener service running quietly on my Linux server. The listener double-checks the notification is legitimate, then writes it neatly into a log file. Wazuh, which is already watching that log file, picks up the new entry, processes it, and raises it as an alert I can see and act on.

No open ports, no exposed servers, and no manual checking of Cloudflare's dashboard, the alerts now just show up where all my other security monitoring already lives.

Why this matters

This project turned a manual, easy-to-forget task, periodically remembering to check Cloudflare for new security insights, into an automated one that fits naturally into my existing monitoring setup. It's a small piece of infrastructure, but it closes a real gap: Cloudflare's own scans are only useful if someone actually sees the results in time to act.

It's also a good example of something I like about running your own security stack: when two tools don't talk to each other out of the box, you don't have to wait for a vendor to build that integration. Sometimes a few hours with a lightweight script and the right connective glue, like a Cloudflare Tunnel, gets you there yourself.

What's next

The listener is live and reliably passing alerts through to Wazuh. The next step is refining how those alerts are categorized once they land, so that a genuinely dangerous misconfiguration, like an exposed origin server, stands out clearly from lower-priority notices, instead of everything landing at the same level of urgency.

September 2026 · Public notice

isf.govlb.cam is not the Internal Security Forces

Over the past few days, a fake website impersonating Lebanon's Internal Security Forces (ISF) has been circulating via email and SMS. It tells recipients they have an outstanding traffic violation and directs them to pay a fine through a link. The site is not affiliated with the ISF in any way, and no payment information should ever be entered there.

The real domain vs. the fake one

The genuine ISF website is isf.gov.lb. The fraudulent site uses isf.govlb.cam. Two differences are built to be easy to miss at a glance.

Official
isf.gov.lb
Fraudulent
isf.govlb.cam

The official .gov.lb structure is collapsed into a single fake-looking word, govlb, and the domain ends in .cam rather than .com or .lb. Visiting the bare domain loads nothing. The scam only works through the specific link sent in the phishing message (isf.govlb.cam/traffic-tickets), which is typical of phishing infrastructure: built to be reached only through the message, not browsed to directly.

What the fake page actually shows

The page mimics an official traffic-violation lookup: a plate number field, a fabricated "speed limit infringement" notice citing a real-sounding Lebanese traffic law, a detailed fine breakdown, and a time-pressured "50% discount if paid within 7 days." It's a classic urgency tactic meant to push a quick payment before anyone stops to check whether the site is real.

The page's input handling is also a giveaway of how thin the site actually is: entering an obviously invalid plate number still returns a "verified" result and a generated fine. A real government lookup system checks input against actual records; this one appears to accept anything.

What to do if you received this

  • Don't click the link. If you already did, don't enter any information on the page.
  • If you entered payment or personal information, contact your bank immediately and monitor your accounts.
  • Verify any traffic-violation claim only through isf.gov.lb directly, never through a link in an email or SMS.
  • Report the message through the ISF's Balligh platform.