Projects & Tooling

Defensive security tools, compliance automation apps, and active open-source repositories.

// DEFENSIVE_RESEARCH_POLICY: SuhLabs publishes defensive research and compliance tooling. Recon and simulation work is for authorized environments only.

// PUBLISHED_SPLUNK_APPS_&_COMMUNITY_ARTICLES

[VIEW_GITHUB_PROFILE →]

Zero Trust Compliance

SPLUNKBASE 9582

Translates DoD Zero Trust Execution Roadmaps and NIST 800-207 into automated, telemetry-driven proof of delivery. Structures evidence ingestion across all 7 ZT Pillars with log-based audit readiness.

Splunk App Zero Trust DoD COA / NIST
Splunkbase #9582 → Whitepaper → Community Blog →

AWS-DFD-Visualizer

SPLUNKBASE 8628

Renders complex multi-cloud architecture into dynamic, audit-ready Zero Trust topology blueprints across NIST 800-207 Three-Plane Swimlanes (Identity, Policy, Infrastructure). Built for DoD IL5.

JavaScript Zero Trust NIST 800-207
GitHub → Splunkbase #8628 →

TA-suhlabs-eMASS

SPLUNKBASE 8253

Splunk Technology Add-on for automated eMASS Plan of Action & Milestones (POA&M) data collection. Directly converts raw security data into structured RMF audit-ready evidence.

Python Splunk TA eMASS / RMF
GitHub → Splunkbase #8253 →

Asset & Identity in Splunk ES

SPLUNK COMMUNITY

Splunk Technology Add-on (TA) and architectural guide for building reliable, automated Asset and Identity (A&I) frameworks inside Splunk Enterprise Security. Details entity resolution, deduplication pipelines, and multi-source reconciliation.

Splunk ES Asset & Identity Splunk TA
View on GitHub → Read on Splunk Community →

// OPEN_SOURCE_DEFENSIVE_TOOLING_&_REPOSITORIES

ai-agent-governance-framework

Reference architecture and tooling for mechanical control planes in autonomous coding teams. Enforces frozen schemas, read-only test mountings, Git worktree isolation, and deny-by-default egress sandboxes.

AI_GOVERNANCE CONTROL_PLANES
Clone Repository → Whitepaper →

okta-recon-generator

Defensive identity-provider reconnaissance tool for authorized assessments (a tenant you own or have written permission to test). Audits stale credentials, MFA coverage, and inactive admin accounts.

DEFENSIVE_RECON IDENTITY_AUDIT
View on GitHub →

purple-apt-cicd-recon

Purple-team CI/CD attack-path simulation templates for labs and authorized programs. Built specifically for detection engineering and software supply chain posture auditing.

PURPLE_TEAM CI_CD_SECURITY
View on GitHub →

Cloud-AIDevSecOps-Templates

Hardened infrastructure-as-code and CI/CD pipeline security templates. Incorporates static analysis gates, secret scanning rules, and automated vulnerability check workflows.

DEVSECOPS PIPELINE_SECURITY
View on GitHub →