Skip to content
View brianhannigan's full-sized avatar

Block or report brianhannigan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
brianhannigan/README.md

Brian Hannigan β€” Animated Header

Architecture Map

Architecture (Cyber Pillar + Bidirectional Pulses)


πŸ›  Current Work

Active writing and systems engineering work that I want easy to find from the top of the profile.

Systems Administrator Field Guide banner

πŸ“˜ Systems Administrator Field Guide

A practical field guide for systems engineering, operational thinking, documentation, and building dependable mission-focused systems.

  • Applied systems engineering patterns
  • Field-ready documentation and operational guidance
  • Reference material for disciplined engineering execution

View repository β†’


⚑ Featured Projects

Product-style repositories with demos, architecture, and deployable workflows.

Vulnerability Management Program banner

πŸ›‘οΈ Vulnerability Management Program

End-to-end vulnerability management workflows for continuous scanning, risk prioritization, and remediation tracking.

  • Structured vulnerability assessment lifecycle
  • Risk-based remediation planning
  • Compliance-oriented documentation practices

View repository β†’

SOC Azuki import/export project banner

🍡 SOC Investigation Azuki (Import/Export)

Hands-on SOC investigation workflows for importing and exporting case data with practical triage and analysis patterns.

  • SOC case import/export investigation workflow
  • Analyst-oriented triage and data handling patterns
  • Documentation-first approach for repeatable operations

View repository β†’

thebrokerhunt project banner

πŸ•΅οΈ thebrokerhunt

Threat-intelligence style project focused on broker ecosystem analysis and investigative workflows.

  • Broker-hunt documentation and research notes
  • Investigation-first workflow design
  • Structured, repeatable intelligence process

View repository β†’

Threat hunting project banner

πŸ›‘ Threat Hunting (KQL / SIEM)

Practical threat-hunting playbooks and detection engineering workflows for SOC-style investigations.

  • KQL investigations & correlations
  • Attack chain reasoning & hypotheses
  • Documentation-first, repeatable hunts

View repository β†’

Portable Translator project banner

🧠 Portable Translator (Offline AI)

Self-contained OCR + offline translation engine built for field use and disconnected environments.

  • WPF UI + embedded Python orchestration
  • Tesseract OCR + Argos / Marian NMT
  • Local APIs, health checks, PID management, audit logging

View repository β†’

SurgicalVisualization project banner

🧬 SurgicalVisualization (3D Medical)

3D model inspection platform for surgical / medical STL/OBJ workflows with desktop + web engines.

  • WPF + HelixToolkit for desktop rendering
  • Three.js browser engine for web-based inspection
  • Mesh inspection, camera controls, visualization tools

View repository β†’

thebuyerhunt threat hunt banner

🧾 thebuyerhunt

A published threat hunt focused on buyer-themed intrusion patterns, investigative logic, and repeatable analyst workflows.

  • Documented hunt methodology and hypotheses
  • Threat hunting workflow built for analyst reuse
  • Direct access to the specific hunt write-up

Open hunt write-up β†’



πŸ”₯ Mission

I build secure, intelligent, mission-critical systems designed to operate in real-world environments.

From DoD simulation platforms to offline AI translation engines, my work blends:

  • πŸ›‘ Cybersecurity & Compliance
  • 🧠 AI / LLM Systems
  • πŸ–₯ Desktop & 3D Visualization Applications
  • βš™οΈ Infrastructure Automation
  • πŸ” Zero-Trust Architectures

🧭 Portfolio Navigation

πŸ›‘οΈ IT & Cybersecurity

I'm passionate about cybersecurity and enjoy solving complex, real-world security challenges through hands-on projects.
My work spans vulnerability management, threat detection, and security operationsβ€”focused on practical impact, not theory.

🧠 AI & Intelligent Systems

πŸ”Ή Portable Translator (Offline AI Translation Engine)

Self-contained OCR + AI translation platform with embedded Python and local model hosting.

Highlights

  • Argos + Marian NMT support
  • Embedded Tesseract OCR
  • Offline model hosting
  • Local API services
  • WPF + Python hybrid architecture
  • Secure background service orchestration

Language Translator

LinguoAI translator animated demo


πŸ”Ή SurgicalVisualization (3D Medical Engine)

HelixToolkit + Three.js 3D model inspection and surgical analysis platform.

Highlights

  • STL / OBJ 3D rendering
  • Desktop (WPF) + Web (Three.js) dual engine
  • Camera control + mesh inspection
  • Precision zoom + lighting control
  • Clean dark-mode surgical UI

Medical 3D Simulator (SurgicalVisualization)

3D medical visualization and simulation project focused on surgical anatomy exploration and training. image


πŸ›‘ Cybersecurity & Intelligence Engineering

πŸ”Ή Threat Hunting & Detection Engineering

  • KQL investigations
  • Log correlation
  • SIEM analytics
  • Incident triage workflows
  • Detection engineering
  • SOC data import/export analysis workflows

πŸ”— Example Repository:
https://github.com/brianhannigan/kql-threathunting-beginner-guide

πŸ”— SOC Investigation Import/Export Repository:
https://github.com/brianhannigan/soc-investigation-azuki-import-export


πŸ”Ή Vulnerability & Compliance Engineering

  • Nessus scanning
  • DISA STIG remediation
  • Patch validation
  • Secure configuration baselines
  • Risk tracking & documentation

🧱 Infrastructure & Systems Engineering

  • Docker-based service orchestration
  • QEMU + Ubuntu VM automation
  • Offline deployment packaging
  • Embedded Python distribution
  • Windows service wrappers
  • Local API hosting
  • Structured logging systems

πŸ— Architecture Philosophy

I design systems using layered separation of concerns:

User Interface Layer
        ↓
Application Logic Layer
        ↓
Service Orchestration Layer
        ↓
Isolated Engine Layer
        ↓
Secure Local or Remote Models

Core Principles

βœ” Offline-first when possible
βœ” Zero-trust boundaries
βœ” Clear separation of concerns
βœ” Reproducible deployment
βœ” Deterministic startup & logging
βœ” Secure configuration management


🎬 Product-Style Engineering

Each major repository is structured like a product launch, not just a code dump.

Includes:

  • Animated SVG workflows
  • UI state transitions
  • Before/after visual demos
  • Architecture diagrams
  • Installation walkthroughs
  • Clean documentation hierarchy

My goal is not just to build software β€”
but to build deployable systems with clarity and confidence.


πŸ“Š Technical Stack

Languages

  • C#
  • Python
  • JavaScript / TypeScript
  • PowerShell
  • SQL

Frameworks & Platforms

  • .NET / WPF
  • HelixToolkit
  • Three.js
  • Docker
  • Argos Translate
  • Marian NMT
  • Tesseract OCR
  • QEMU
  • GitHub Actions

🧩 Current Focus Areas

  • Advanced AI model orchestration
  • Self-contained deployable systems
  • Offline enterprise AI tooling
  • Intelligent threat analysis
  • 3D visualization engines
  • Zero-trust application design
  • Hybrid desktop + web architectures

πŸ› Professional Background

  • 14+ years supporting Government projects
  • Mission-critical system development
  • Secure enterprise deployments
  • Cybersecurity engineering
  • Technical architecture & leadership
  • AI-powered application design

🀝 Connect

LinkedIn: https://www.linkedin.com/in/brianhannigan/
GitHub: https://github.com/brianhannigan


πŸ“Œ What This Profile Represents

This is not a collection of school projects.

This is a working laboratory of:

  • Deployable AI systems
  • Production-grade architectures
  • Secure engineering practices
  • Real-world infrastructure tooling
  • Advanced visualization engines

I build systems that are:

Secure. Intelligent. Deployable.

πŸ” SOC / MSS Security Work (Highlights)

I focus on practical, operations-ready security work: alert triage, vulnerability scanning, secure configuration, and clear client-facing reporting.


⚠️ Vulnerability Management Projects -- UPDATING

  • πŸ” Vulnerability Management Program Implementation
    End-to-end vulnerability management workflow covering discovery, prioritization, remediation, and reporting.

  • πŸ› οΈ Programmatic Vulnerability Remediations (PowerShell & Bash)
    Automated remediation scripts for common security findings across Windows and Linux environments.


🚨 Threat Hunting & Security Operations -- UPDATING

  • πŸΎπŸ” Threat Hunting Scenario - CloutHaus
    Phishing β†’ Mailbox Compromise β†’ Exfiltration (KQL Case Study)

  • πŸ•΅οΈ Threat Hunting Scenario – TOR Browser Usage
    Detection and investigation of anonymization tools within enterprise environments using realistic SOC workflows.

  • πŸ€– Automated Incident Tracking
    Streamlined incident intake and tracking to support SOC reporting and response workflows.

  • πŸ•΅οΈ SOC Agent Lab
    Autonomous AI agents for SOC alert triage, detection engineering, and log intelligence.

  • πŸ“Š SIEM Engineering Lab
    Detection engineering and log-analysis workflows for practical SOC operations.

  • πŸ›°οΈ Secure Infrastructure Observability Lab
    Security-focused observability pipelines for resilient and monitorable infrastructure.

  • βœ… Compliance Automation Toolkit Lab
    Automation-driven compliance checks and reporting to reduce manual security overhead.


Artificial Intelligence \ Machine Learning -- UPDATING

  • Lightweight Finetuning Foundation Models

    Apply parameter-efficient fine-tuning (PEFT) to adapt a pretrained Hugging Face model for a text classification task, then compare baseline and fine-tuned performance.

πŸ›‘οΈ Software Development

C#

  • ** Screen Sender
  • **

Python

Powershell

  • ** Project Creator

Full Stack React


Core Skills

  • SOC Operations: alert triage, incident documentation, escalation workflows
  • Vulnerability Management: Nessus scanning, findings documentation, remediation tracking
  • Compliance & Hardening: DISA STIG-aligned secure configuration (Windows/Linux fundamentals)
  • Security Awareness: phishing/social engineering readiness, training & reporting
  • Tooling: Git, VMware, Docker, scripting (Python/PowerShell/Bash)

What I Deliver

  • Clean documentation (SOPs/runbooks) that makes security repeatable
  • Signal-over-noise mindset for tuning and validating alerts
  • Customer-ready status updates and summaries that drive action

🀝 Connect With Me


πŸ”’ Focused on building secure, resilient systems and training the next generation of engineers and defenders.

Focused Areas: β€’ SIEM Engineering & Log Analysis β€’ Infrastructure Observability β€’ Secure Configuration (STIG/Nessus) β€’ Security Automation (Python/Bash) β€’ Threat Detection Workflows

Popular repositories Loading

  1. kql-threathunting-beginner-guide kql-threathunting-beginner-guide Public

    KQL Log Analysis & Threat Hunting – Complete Beginner to Practitioner Guide

    PowerShell 1

  2. test-github test-github Public

  3. projects projects Public

    C#

  4. datasciencetoolkit datasciencetoolkit Public

  5. datasharing datasharing Public

    Forked from jtleek/datasharing

    The Leek group guide to data sharing

  6. github-demo github-demo Public

    A simple demo repository to show basic Git workflow