Skip to content
View stefanutc1's full-sized avatar

Block or report stefanutc1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
stefanutc1/README.md

Enterprise Portal & Research Datacenter Infrastructure IaC Institutional Monorepo & Thesis Historical Engineering Archive


[01] · Executive Profile & Engineering Governance

Senior Systems Architect · Infrastructure & Cloud Operations · Applied Threat Intelligence Lead

I am Moană Ștefănuț-Cornel (@stefanutc1), an Enterprise Systems Architect, Hybrid Cloud Infrastructure Engineer, and Cybersecurity Threat Intelligence Specialist (DFIR & Incident Management), currently completing a B.Sc. in Business Informatics at the University of Craiova — Faculty of Economics and Business Administration (FEAA, 2024 – 2027).

With continuous hands-on software and systems engineering leadership since 2015 (10+ years of operational delivery, preserved in the stefanutc1/old archive), my engineering practice is anchored around three core corporate and institutional pillars:

  • Mission-Critical Financial Core Systems (Bachelor's Thesis @ FEAA): Engineering and validating an enterprise-grade Core-Banking Transaction Engine & PCI-DSS v4.0 Payment Gateway featuring a PostgreSQL ACID Double-Entry General Ledger (SELECT ... FOR UPDATE pessimistic concurrency control & SERIALIZABLE isolation), Java 17 (Spring Boot 3.2) microservice mesh, automated tokenization, Python FastAPI real-time fraud risk scoring, and Wazuh SIEM/XDR threat detection verified across 5 automated MITRE ATT&CK adversarial scenarios.
  • Corporate Incident Response, Threat Intelligence & Forensic Disclosure: Reverse-engineering sophisticated distributed phishing and financial fraud operations (e.g., Media Galaxy Brand Spoofing / yiyangsaas.com C2), analyzing Browser-in-the-Middle (BitM) session hijacking (Steam OpenID) and real-time operator vishing relays (Revolut OTP Interception), leading to official National Cybersecurity Directorate (DNSC) Incident Notifications & Takedowns (#178465).
  • Tier-3 Hybrid Datacenter Infrastructure & Zero-Trust Governance: Designing, provisioning, and operating a self-hosted 4-node bare-metal datacenter cluster (Proxmox VE 9.2, OpenMediaVault 7 Enterprise Storage, Apple Silicon ARM64 Compute, Kubernetes k3s Edge Worker), governed by 5 Zero-Trust OPNsense 24.7 802.1Q VLANs, 57 Terraform IaC modules, 18 Ansible roles, and continuous DevSecOps verification gates.

[02] · Enterprise Systems Architecture & Repository Portfolio (2015 – 2027)

Mission-Critical Workloads, Declarative Infrastructure & Academic Engineering Platforms

System Identifier Repository & Live Service Endpoint Lifecycle Enterprise Scope & Architectural Specifications
SYS-WEB stefanutc1/stefanutc1.github.io
↳ 🌐 Enterprise Portal: stefanutc1.github.io
2026 Executive Presentation & Technical Research Journal architected with Next.js 15 (App Router, Static Export) and React 19, implementing high-density information architecture, interactive shell emulator, ⌘K command palette, and 7 comprehensive technical research papers (EN / RO).
SYS-INFRA stefanutc1/infrastructure 2025 – Present 4-Node Hybrid Datacenter & Cloud Operations Platform: Proxmox VE 9.2 (pve, pve2), OpenMediaVault 7 NAS (omv-nas), Bare-Metal k3s Edge Worker (kubernetes), OPNsense 24.7 (5 Zero-Trust VLANs), 57 Terraform IaC modules, 18 Ansible configuration roles, Wazuh SIEM/XDR, Suricata DPI, and industrial ESP32 telemetry firmware.
SYS-THESIS stefanutc1/university 2024 – 2027 FEAA Institutional Monorepo (43+ Projects) & Core-Banking Thesis Platform: Production Java 17 Spring Boot 3.2 + Angular 20 + PostgreSQL core ledger, DFIR Threat Intelligence dossiers (DNSC #178465), 100% Solved InvataCyber CTF Suite (3/3 Flags), C++ algorithmic engines, C# .NET, Python, and Cisco Packet Tracer enterprise network topologies.
SYS-OLD stefanutc1/old 2015 – 2023 Historical Software Engineering Archive: RedZone SA-MP Roleplay (2015–2016, PAWN & MySQL), NQGaming SA-MP 0.3.7 RPG (2016–2018, 10 factions, custom server-side anti-cheat), Crowland Wiki (2019–2020, Vue 3 & Vite), Kronick Community Portal (2021–2023, PHP/MySQL/Nginx), and Roadman Bot (2022–2023, Python & Docker).

[03] · Applied Research Publications & Technical Dossiers

Executive Summaries of Published Investigations on stefanutc1.github.io

  1. [DOSSIER-01] · Forensic Analysis of the "Media Galaxy" E-Commerce Fraud Syndicate — Infrastructure Attribution & DNSC Takedown #178465
    Decompiling the 8-stage payment skimming and 3D-Secure OTP intercept engine (yiyangsaas.com / 23.224.199.13), followed by coordinated inter-agency takedown via the Romanian National CSIRT (DNSC).
  2. [DOSSIER-02] · Enterprise Core-Banking Architecture: ACID General Ledger, PCI-DSS v4.0 Compliance & SIEM Defense-in-Depth
    Architectural breakdown of the FEAA Bachelor's Thesis platform: mathematical IBAN MOD-97 / Luhn verification, double-spend race condition elimination, and SIEM correlation against 5 MITRE ATT&CK vectors.
  3. [DOSSIER-03] · Engineering a Tier-3 Hybrid Datacenter: Proxmox VE 9.2, 5-VLAN Zero-Trust Segmentation & GitOps IaC
    Operational design of a multi-node bare-metal compute fabric (192.168.1.240, .181, .196, .150), kernel ZRAM memory governance, and zero-cost multi-cloud policy enforcement.
  4. [DOSSIER-04] · Comparative Analysis of Multi-Factor Authentication Bypasses: Steam OpenID BitM vs. Revolut Real-Time Vishing Relays
    Technical evaluation of modern adversary tactics targeting session tokens and automated OTP relay channels, coupled with enterprise detection engineering.
  5. [DOSSIER-05] · Decompilation and Vulnerability Assessment of Fraudulent "Task Optimization" Platforms: /api/v1/site/config Exploits
    Forensic reverse-engineering of deceptive financial web APIs, identifying backend authentication bypasses and SQL injection vectors.
  6. [DOSSIER-06] · InvataCyber.ro CTF (19.09.2026) — Comprehensive Technical Writeup (3/3 Solved · 100% Score): Stored XSS, Blind SQLi & SSTI
    Offensive security walkthrough and 11 automated exploit scripts in Python/JavaScript executing boolean oracle extraction and template injection to RCE.
  7. [DOSSIER-07] · From Distributed Multiplayer Engines in 2015 to Enterprise Hybrid Cloud: Over a Decade of Systems Engineering
    Retrospective evaluation of early concurrent programming, systems design decisions, and architectural evolution across 10+ years of software delivery.

[04] · Enterprise Hybrid Datacenter Topology

Physical Fabric, Zero-Trust Perimeter & Micro-Segmented Virtual Infrastructure

                         [ Enterprise WAN / Cloudflare Zero-Trust Perimeter ]
                                                  │
                                ┌─────────────────▼─────────────────┐
                                │   OPNsense 24.7 Firewall Router   │
                                │ 5 VLANs: MGMT·PROD·CYBER·NAS·IOT  │
                                └─┬──────────┬──────────┬─────────┬─┘
                                  │          │          │         │
                ┌─────────────────▼─┐  ┌─────▼──────────▼─┐  ┌────▼────────────────┐
                │ NODE-1: pve       │  │ NODE-2: omv-nas  │  │ NODE-3 & NODE-4     │
                │ 192.168.1.240     │  │ 192.168.1.181    │  │ .196 (ARM64 pve2)   │
                │ Proxmox VE 9.2    │  │ OpenMediaVault 7 │  │ .150 (k3s Worker)   │
                │ 20+ VM/LXC · SIEM │  │ NFSv4/SMB3 · ZFS │  │ Cilium CNI · ESP32  │
                └───────────────────┘  └──────────────────┘  └─────────────────────┘

[05] · Enterprise Technology Stack & Competency Matrix

Comprehensive Inventory of Operational Languages, Frameworks, Platforms & Protocols

Operational Domain Enterprise Standards, Frameworks & Infrastructure Platforms
Backend & Distributed Systems Java 17 (LTS) · Spring Boot 3.2 · Python 3.12 · FastAPI · C / C++ (STL, POSIX) · C# (.NET 8) · PHP · PAWN
Web Applications & Portals TypeScript 5.7 · Next.js 15 (React 19) · Angular 20 · Vue 3 (Composition API) · Tailwind CSS · REST
Virtualization, Cloud & IaC Proxmox VE 9.2 · Kubernetes (k3s / k0s) · Terraform (57 modules) · Ansible (18 roles) · Docker · Nginx · GitHub Actions CI/CD
Cybersecurity, DFIR & SecOps Wazuh SIEM/XDR 4.14 · Suricata DPI IDS/IPS · OPNsense 24.7 (5 VLANs) · CrowdSec · WireGuard · YARA · MITRE ATT&CK
Enterprise Data & Storage PostgreSQL 16 (ACID Double-Entry) · MySQL 8.0 / MariaDB · Oracle SQL · SQLite WAL · Redis · ZFS Storage Pool

[06] · Institutional Coordinates & Executive Contact

Corporate Channels, Institutional Affiliation & Official Verification

Pinned Loading

  1. infrastructure infrastructure Public

    Production-grade hybrid infrastructure, virtualization & cybersecurity lab: Proxmox VE 9.2, OPNsense L3 firewall, Wazuh SIEM/XDR, Active Directory forest, k3s, declarative NixOS/IaC & banking secur…

    TypeScript 1