Skip to content
View shaurya-security's full-sized avatar

Block or report shaurya-security

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
shaurya-security/README.md

👋 Hi, I'm Aman Kumar (Shaurya)

☁️ Cloud Security • AWS • Terraform • Detection Engineering

AWS Terraform Linux

Note: Most of my open-source work is published under the name Shaurya.

I build production-style AWS security labs that simulate real-world cloud environments using AWS, Terraform, and security automation.

My projects focus on Infrastructure as Code, cloud networking, detection engineering, and SIEM integration.

My goal is to build practical projects that mirror real cloud environments while preparing for a Cloud Security Engineer role.


Featured Projects

🔹 AWS Secure VPC with Terraform

Declarative AWS infrastructure built with Terraform featuring a managed NAT Gateway, AWS Systems Manager (SSM), remote state, GitHub Actions, and Checkov.

Tech: Terraform · AWS · IAM · SSM · NAT Gateway · GitHub Actions · Checkov

View Project


🔹 AWS Infra CLI

Bash-based AWS infrastructure toolkit that provisions VPC networking, EC2, routing, and security groups entirely through the AWS CLI.

Tech: Bash · AWS CLI · VPC · EC2 · Networking

View Project


🔹 AWS Cloud Detection Pipeline

Cloud detection pipeline using CloudTrail, VPC Flow Logs, and Wazuh with custom AWS detection rules and centralized log analysis.

Tech: AWS · CloudTrail · VPC Flow Logs · Wazuh · Detection Engineering

View Project


🔹 Wazuh Active-Response Containment

Automated SSH brute-force detection and containment on AWS using Wazuh Active Response and temporary firewall blocking.

Tech: Wazuh · Active Response · iptables · MITRE ATT&CK · Linux

View Project


💻 Technical Skills

Area Technologies
☁️ Cloud AWS
🏗️ Infrastructure as Code Terraform
🔐 Security IAM, Security Groups, CloudTrail, VPC Flow Logs, Wazuh
🖥️ Compute & Networking EC2, VPC, Route Tables, NAT Gateway, SSM
⚙️ Automation Bash, Python, GitHub Actions
🐧 Platform Linux, Git

🎯 Current Focus

  • 📚 AWS Solutions Architect – Associate
  • 📚 HashiCorp Terraform Associate
  • 🛡️ Cloud Detection Engineering
  • ☁️ AWS Security Architecture

Connect


Building secure cloud infrastructure through hands-on engineering, one project at a time.

Pinned Loading

  1. aws-secure-vpc-with-terraform aws-secure-vpc-with-terraform Public

    managed NAT Gateway (replacing a bastion-as-NAT instance), SSM-only instance access with no SSH exposure, S3 remote state with native locking, and a GitHub Actions pipeline running terraform fmt, t…

    HCL 1

  2. aws-infra-cli aws-infra-cli Public

    AWS infrastructure automation toolkit built with Bash and AWS CLI. 110+ functions across 8 modules managing VPCs, subnets, EC2, NAT, routing, and security groups without Terraform or CloudFormation.

    Shell

  3. aws-cloud-detection-pipeline aws-cloud-detection-pipeline Public

    Cloud-based detection engineering lab using AWS, Wazuh, CloudTrail, VPC Flow Logs, custom detections, and alert investigation.

    Shell

  4. wazuh-active-response-containment wazuh-active-response-containment Public

    Full Automated chain validated: attack → detection → alert → containment → recovery.

    Shell

  5. wazuh-custom-rule-detection wazuh-custom-rule-detection Public

    Custom Wazuh SSH brute force detection lab using Linux Mint, Fedora, and Ubuntu Server VMs with MITRE ATT&CK mapping and SIEM alert validation.

  6. cloud-security-learning-portfolio cloud-security-learning-portfolio Public

    Learning cybersecurity and cloud from scratch - Linux, scripting, AWS, detection, and a self-hosted SIEM. Six phases documented honestly.

    Shell