// cat ./projects/aws-shield-fms.md
Enterprise DDoS Defense
AWS Shield Advanced & Firewall Manager Automation
Multi-account AWS Shield Advanced rollout via Terraform and Firewall Manager, with delegated admin, org-level WAF policies, and Route53 health checks driving automated DDoS mitigation.
## Problem
DDoS protection at organization scale is brittle when applied account-by-account. Drift, missing protections on new resources, and inconsistent WAF policies leave gaps the moment a new workload ships.
## Architecture
AWS Organizations with a dedicated security delegated admin account hosts Firewall Manager policies. Terraform modules codify Shield Advanced protections, WAF rule groups, and FMS policy bindings across the org. Route53 health checks feed proactive engagement triggers.
## Automation
New accounts inherit protections automatically; resource-level Shield enrollment is enforced through FMS policies. Health-check-driven failover and DRT engagement playbooks are versioned alongside the infra code.
## Outcome
Consistent edge protection across every account, zero-touch onboarding for new workloads, and an auditable, drift-resistant DDoS posture.
// ls ../
FLAGSHIP
Snock →
Autonomous Cloud Security AI Agent
RESEARCH
SpecterHeal →
AI-Assisted Self-Healing Infrastructure
PRODUCTION
Hardened GitLab DevSecOps Platform →
Secure CI/CD with Terraform, tfsec, Trivy, SonarQube
ENGAGEMENT
Trend Micro XDR Remediation →
Enterprise Endpoint Detection & Response Tuning
PRODUCTION
AWS Incident Response Automation →
Event-Driven Containment with Lambda + CloudWatch
PRODUCTION
SOC Automation & Visualization →
TheHive + Elasticsearch + Grafana + n8n
PRODUCTION
Fortinet SD-WAN Deployment →
Resilient Multi-Site Connectivity
INTERNAL
CTF Training Platform →
Practical Cybersecurity Training Lab
PRODUCTION
Cloud Monitoring & Observability Platform →
Terraform, ECS Fargate, cross-account CloudWatch
DELIVERED
CIS Benchmark & Remediation Program →
Measured posture improvement across a DevOps platform
DELIVERED
Open Banking Auth Flow Load Testing →
k6, mTLS, FAPI/OAuth2 with PAR, browser-driven SCA