Skip to content
View solomonneas's full-sized avatar

Sponsoring

@openclaw

Block or report solomonneas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
solomonneas/README.md

Yellow πŸ‘‹, I'm Solomon

I'm a Network & Systems Engineer / Teaching Lab Aid focused on cybersecurity, network observability, and AI infrastructure. I build SOC tooling, MCP servers, and agent workflows that run on real production gear, not toy demos. I write about it at solomonneas.dev/blog.

  • US flag US based in Tampa, FL, near the beach.
  • πŸŽ“ M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
  • πŸ›‘οΈ Building open-source SOC + threat intel tooling on bare-metal Proxmox.
  • πŸ”­ Deep in multi-agent orchestration, MCP servers, and detection engineering.
  • πŸͺ’ n8n enthusiast, wiring up self-hosted automation for intel pipelines, monitoring, and SOC ops.
  • 🌱 Currently exploring self-hosted AI stacks, network observability, and incident response automation.
  • ✍️ Writing regularly on my blog, Dev.to, Hashnode, CoderLegion, and X.
  • πŸ’¬ Ask me about Proxmox migrations, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
  • βš™οΈ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
  • πŸ‘¨β€πŸ‘§ Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
  • β˜• If my work helped you, buy me a coffee or tip on Ko-fi.
  • πŸ“« Reach me at me@solomonneas.dev Β· LinkedIn Β· X Β· Bluesky Β· Mastodon

Some of the projects I've built or maintain:

OpenClaw & Dev Tools

  • πŸ” code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
  • πŸ“˜ openclaw-best-practices - Production runbooks for security hardening, multi-model orchestration, and recovery.
  • πŸ“Š usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
  • πŸ“š prompt-library - Dual-mode prompt management with browse/copy UI and a REST API for sub-agents.
  • πŸ›‚ content-guard - Policy-driven content scanning and publish checks.

Security & Threat Intelligence

  • πŸ›‘οΈ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
  • πŸ” bro-hunter - Threat hunting for Zeek and Suricata logs with beaconing detection and MITRE mapping.
  • πŸ”¬ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
  • πŸ“– hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
  • πŸ—οΈ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.

MCP Servers

  • 🧠 cortex-mcp - Observable analysis for IOCs, reports, and response actions.
  • πŸ›‘οΈ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
  • πŸ”¬ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
  • 🐝 thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
  • βš”οΈ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
  • πŸ”Ž zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
  • πŸ¦” suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
  • πŸ•ΈοΈ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
  • βš™οΈ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.

Network & Infrastructure

  • πŸ”­ watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
  • πŸ”Œ portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
  • πŸ”’ proxguard - Proxmox firewall rule visualization with conflict detection and rule simulation.
  • 🐧 samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.

Media Automation

  • πŸ“Ί media-cli - Single-file bash CLI for Sonarr, Radarr, Prowlarr, qBittorrent, Bazarr, Jellyseerr, and Tdarr.
  • 🎬 jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.

Currently Contributing To

  • πŸ§ƒ vincentkoc/tokenjuice - Lean output compaction for terminal-heavy agent workflows.
  • πŸ“ steipete/summarize - Fast summaries from URLs, files, and media. CLI + Chrome Side Panel + Firefox Sidebar with video slides, OCR, and transcript extraction.
  • πŸ“¬ steipete/gogcli - Google Suite CLI for Gmail, Calendar, Drive, and Contacts.
  • 🦞 openclaw/plugin-inspector - Offline compatibility inspector for mocking OpenClaw and testing plugins.
  • πŸ’¬ steipete/discrawl - CLI for Discord with a SQLite backend.

More to come as PRs land.

I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.

Featured Writing

Infrastructure Migrations

SOC & Security Operations

Network Engineering

Agents & AI Infrastructure

Popular repositories Loading

  1. mitre-mcp mitre-mcp Public

    MCP server for MITRE ATT&CK knowledge base. Map alerts to techniques, profile threat groups, analyze detection gaps, and enrich SOC workflows with adversary intelligence.

    TypeScript 2

  2. solomonneas solomonneas Public

    My personal repository.

    1

  3. rapid7-mcp rapid7-mcp Public

    MCP server for Rapid7 InsightIDR β€” SIEM log search, investigations, alerts, UBA, and threat intelligence

    TypeScript 1

  4. proxguard proxguard Public

    Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts

    TypeScript 1

  5. openclaw-best-practices openclaw-best-practices Public

    Practical guides for running OpenClaw in production. Security hardening, infrastructure patterns, agent orchestration, and operational runbooks from real deployments.

    Python 1

  6. maltego-mcp maltego-mcp Public

    MCP server for authoring Maltego .mtgx graphs and running primitive OSINT lookups (whois/DNS/ASN/crt.sh). Composes with misp-mcp, thehive-mcp, and other security MCPs.

    Python 1