Skip to content
View toluowo's full-sized avatar
  • EDTL

Block or report toluowo

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
toluowo/README.md

Tolu Owolabi

Security Engineer | AI Security | Detection Engineering | Security Automation

I build and investigate security systems across AI security, detection engineering, vulnerability management, cloud security, identity, and security automation.

My background spans cybersecurity analysis, IT infrastructure, software development, and hands-on security labs. I use that combination to build practical security tooling, simulate attacks in controlled environments, engineer detections, and turn security evidence into actionable findings.

What I work on

  • 🔐 Security Engineering — Python security tooling, automation, evidence-driven assessment
  • 🤖 AI Security — adversarial testing, prompt injection, jailbreak evaluation, AI red teaming
  • 🛡️ Detection Engineering — Wazuh, Microsoft Sentinel, SIEM analytics, endpoint telemetry
  • 🎯 Vulnerability Management — vulnerability assessment, prioritization, remediation and validation
  • ☁️ Cloud Security — Azure, Microsoft Sentinel and cloud-focused security monitoring
  • 🏢 Identity Security — Active Directory, Windows security and privilege management
  • ⚔️ Offensive Security — controlled reconnaissance, attack simulation and security testing

Featured Security Engineering Projects

🤖 AI Security

AI Red Teaming Lab
Adversarial AI-security training environment covering prompt injection, jailbreak testing, risk classification, scoring and repeatable security evaluation.

🛠️ Security Engineering

AI-RECON
Modular Python security-assessment tooling that collects external evidence, normalizes findings, analyzes exposure and produces console/JSON reports. Built with testing, type checking, packaging and CI validation.

🛡️ Detection Engineering

Wazuh Detection Engineering Lab
Endpoint-security lab demonstrating SSH brute-force telemetry, Wazuh detection, investigation and File Integrity Monitoring.

☁️ Cloud SIEM

Microsoft Sentinel Detection Engineering Lab
Azure/Microsoft Sentinel lab demonstrating Windows RDP telemetry, enrichment, SIEM ingestion, threat investigation and geographic visualization.

🎯 Vulnerability Management

Vulnerability Management with Nessus
End-to-end vulnerability-management workflow covering discovery, authenticated assessment, prioritization, remediation, hardening and verification planning.

🏢 Identity & Windows Security

Active Directory Security Lab
Windows identity-security environment covering domain-controller deployment, network segmentation, users, organizational units, privilege boundaries and the foundation for controlled AD security testing.

Security Stack

SIEM / Detection: Wazuh · Microsoft Sentinel · Splunk · Elastic · Graylog
Endpoint / IR: Microsoft Defender · SentinelOne · Velociraptor · OPSWAT
Network Security: Wireshark · Suricata · Zeek · Nmap
Vulnerability Management: Nessus · OpenVAS / Greenbone · OWASP ZAP · Nikto
Cloud / DevSecOps: Azure · Docker · GitHub Actions · SonarQube
Security Engineering: Python · Bash · Git · REST APIs · JSON · CI/CD
AI Security: Prompt Injection Testing · Jailbreak Evaluation · AI Red Teaming · LLM Security Evaluation

Engineering Approach

I care about more than running security tools. My projects emphasize:

Security Problem
      ↓
Controlled Test / Evidence
      ↓
Detection or Analysis
      ↓
Structured Findings
      ↓
Remediation / Hardening
      ↓
Validation

Where possible, I document what was tested, what evidence was observed, what the result means, and how the control can be improved.

Current Focus

I'm currently deepening my work in:

  • AI security and adversarial testing
  • Detection engineering
  • Security automation with Python
  • Cloud security
  • Vulnerability and exposure management
  • Security engineering for modern AI-enabled systems

Connect


Build it. Break it. Detect it. Fix it. Validate it.

Pinned Loading

  1. ai-red-teaming-lab ai-red-teaming-lab Public

    Hands-on AI security assessment lab with a synthetic vulnerable target, reproducible LLM red-team challenges, evidence-driven evaluation, and remediation retesting.

    Python

  2. ai-recon ai-recon Public

    AI-assisted, offline-first recon CLI. WHOIS, Shodan, AI summary/pretext, live risk score, Markdown reports. AI-assisted recon CLI (offline-first, flips to real APIs with keys)

    Python

  3. Detect-SSH-Brute-Force-Attack-and-FIM-with-Wazuh Detect-SSH-Brute-Force-Attack-and-FIM-with-Wazuh Public

    Wazuh detection engineering lab for SSH brute-force activity, endpoint telemetry, and File Integrity Monitoring.

  4. SIEM-Sentinel-Lab SIEM-Sentinel-Lab Public

    Microsoft Sentinel SIEM lab for RDP honeypot telemetry, threat enrichment, detection, and investigation.

    PowerShell

  5. Vulnerability-Management-with-Nessus-Essentials Vulnerability-Management-with-Nessus-Essentials Public

    End-to-end vulnerability management lab covering discovery, authenticated assessment, prioritization, remediation, and verification.

  6. Active-Directory-Lab Active-Directory-Lab Public

    Active Directory security lab covering identity infrastructure, privilege boundaries, domain administration, and Windows security.

    PowerShell