Cloud AppSec & APIs
How web apps and APIs actually break at the edge — and what holds when traffic gets weird.
Austin · cloud appsec · labs in public
Cloud application security, API protection, and detection engineering — learned in public, served with coffee.
I’m Terminals & Coffee — a builder who sits with how applications really behave, then makes them harder to abuse. Days look like cloud AppSec and API protection; nights look like detection triage with a compliance-minded lens.
Public work is the lab bench: detection-as-code, AI/LLM threat models, cloud automation, architecture notes. Not a highlight reel — learning where the seams show.
How web apps and APIs actually break at the edge — and what holds when traffic gets weird.
SIEM triage with a compliance-minded eye: fewer false positives, clearer signal, regulated environments.
Reproducible benches — Terraform, detection-as-code, AI/LLM security — seams visible on purpose.
Notes on cloud, security, Terraform, and AI security that prefer clarity over theater.
Public labs on GitHub — open the repo if you want the seams.
Wazuh, Sysmon, Elastic/KQL rules, ATT&CK mappings, and reproducible validation workflows.
Hands-on fundamentals for detection engineering — blue-team practice in the open.
Threat models, trust boundaries, secure RAG/agent design, and architecture review exercises.
Multi-cloud automation scripts in Python, PowerShell, and Bash for AWS and Azure.
Study notes and labs for Terraform fundamentals and HashiCorp Associate prep.
Cloud design, threat modeling, risk assessment, and framework-driven decisions.
I build learning paths for people who want cloud security skills they can actually use — attack-and-defend labs, cloud engineering fundamentals, and the habits that keep environments harder to break. Same vibe as Terminals & Coffee: practical, public, no fluff.
No résumé chronology here — just the places I publish and ship.