E. Ologunde Case file

Scene 03 of 06Evidence roomCase file: E. Ologunde

Scene 03

Evidence room

Exhibit A is the photograph on the first page. B, C, E and F are the work; D, the AI thread, has its own page next.

In plain English: this page is the proof behind the claims on the first page: real numbers from real systems, a doctoral project, software and writing.

A route is a set of claims. These are the artifacts behind mine: numbers from a lab that is running right now, figures from doctoral coursework, software with its security design written down, and a public written record.

Exhibit BSecurity monitoring lab

Two small machines, one log pipeline, and the numbers it produced

In plain English: I built a small version of a company’s security monitoring center at home. It collects records of what every device does and flags anything suspicious, so I can test tools before I recommend them to clients.

Collected: live searches over the lab’s SIEM indexHandling: redrawn as sanitized excerptsAddresses and hostnames: withheld on purpose

304,708
events in 24 hours, one index
5
log sources: firewall, DNS, proxy, containers, host agents
~3,700
host-based detection alerts over 7 days
2
Proxmox VE nodes, deliberately unclustered
A SIEM search over the homelab index returning 304,708 events in 24 hours from five sources: docker 167,841, pihole 62,462, linux syslog 38,297, opnsense 35,477 and wazuh 631, with a stacked bar chart of volume every two hours by source.
B.1 Real results from a live search, redrawn: source names and counts only.

Why it exists

Before I recommend SIEM, host-based detection or monitoring tooling to a Cyntraix client, I run it here. Scheduled searches produce a daily digest and a critical-event watch under a search-only service account that can read one index and nothing else.

What it caught

A VPN container that had never worked, crash-looping more than 12,000 times and writing about 361 GB to disk. It is gone now, and so is its agent.

Full lab write-up

Diagram of the security monitoring lab: firewall, DNS sinkhole, reverse proxy, containers and Linux hosts, and host-based detection forward over syslog into one SIEM index, which feeds scheduled detection searches and alerting, with uptime checks, reachability and device discovery alongside.
B.2 Architecture, by role. No addresses, by design.
Top host-based detection alerts over 7 days by rule and level, about 3,700 in total, dominated by one rootcheck rule.
B.3 Host-based alerts over 7 days by rule and level. One noisy rootcheck rule dominates, which is itself a finding.

Exhibit CBreakwater, doctoral coursework

Evidence-bounded vulnerability intelligence for a simulated OT/IoT network

In plain English: for my doctorate I built software that finds the devices on a simulated network of cameras, routers and other connected equipment, looks up their known security flaws, and ranks which ones to fix first. It only counts what it can prove.

Course: SEAS 8414, Analytical Tools for Cyber, George Washington UniversityNetwork: simulated containers onlySubnet: withheld even though it is fake

Breakwater is an end-to-end security-analytics pipeline I built one phase at a time: asset discovery, device identity, vulnerability triage, attack paths, a digital twin for testing fixes, and post-quantum readiness. The rule running through it is the one forensics taught me: nothing counts until something independent backs it. A device is only admitted when it answers; an identity is only trusted when separate witnesses agree; a CVE is only scored for an identity that passed that gate. An ACM-format paper is in preparation.

C.1 Discovery ledger: what was declared, what answered

Declared
26
Found
19
Infrastructure
1
Admitted
20
Missed
7
Phantom
0
  • Hikvision camerafound
  • Dahua NVRfound
  • Axis camerafound
  • Reolink camerafound
  • Dahua camerafound
  • Chromecastfound
  • Hue bridgefound
  • Sonos speakerfound
  • Apple TVfound
  • Synology NASfound
  • QNAP NASfound
  • TP-Link routerfound
  • TP-Link routerfound
  • HP printerfound
  • Raspberry Pifound
  • Unnamed web hostfound
  • Ring doorbellfound
  • Samsung TVfound
  • Nest thermostatfound
  • Nest camerano port
  • Echo Dotno port
  • Cloud endpointno port
  • Cloud endpointno port
  • Cloud endpointno port
  • Cloud endpointno port
  • Cloud endpointno port
  • MQTT brokerinfra
  • 19 declared devices found
  • 7 missed: cloud-style, no local listening port
  • 1 extra: the MQTT broker, which ground truth lists as infrastructure. 19 + 1 = 20 admitted, 77% of the declared 26, 0 phantom hosts
248
NVD CVEs matched: 60 critical, 76 high, 107 medium, 5 low
19
default-credential findings, proven on the simulation only

The seven misses are the ceiling for every later phase: no amount of triage can assess a device that never answered, so the report names them instead of scoping them out.

C.2 Evidence graph and fused triage

Breakwater evidence graph, OpenSSH 8.4p1 on a simulated lab router Directed graph with 23 nodes and 22 edges from a doctoral coursework notebook run. A simulated lab router exposes SSH on TCP port 22, identified as OpenSSH 8.4p1. The CPE is affected by ten CVEs, each linked to one patch or mitigate action. Ranked by fused triage score: CVE-2023-38408 score 16.24 (CVSS 9.8, EPSS 0.64); CVE-2025-26465 score 13.05 (CVSS 6.8, EPSS 0.62); CVE-2023-48795 score 11.32 (CVSS 5.9, EPSS 0.54); CVE-2008-3844 score 9.57 (CVSS 9.3, EPSS 0.03); CVE-2023-51385 score 8.22 (CVSS 6.5, EPSS 0.17); CVE-2026-35385 score 7.51 (CVSS 7.5, EPSS 0.00); CVE-2021-28041 score 7.13 (CVSS 7.1, EPSS 0.00); CVE-2021-41617 score 7.03 (CVSS 7.0, EPSS 0.00); CVE-2023-51767 score 7.00 (CVSS 7.0, EPSS 0.00); CVE-2016-20012 score 6.76 (CVSS 5.3, EPSS 0.15). None of the ten is in the CISA KEV catalog. ASSET SERVICE CPE CVE (CVSS / EPSS) ACTION, BY FUSED SCORE Lab routersimulated SSHTCP 22 OpenSSH 8.4p1cpe:2.3:a:openbsd exposesidentified as CVE-2023-38408 9.8 / 0.644 16.24 CVE-2025-26465 6.8 / 0.625 13.05 CVE-2023-48795 5.9 / 0.542 11.32 CVE-2008-3844 9.3 / 0.027 9.57 CVE-2023-51385 6.5 / 0.172 8.22 CVE-2026-35385 7.5 / 0.001 7.51 CVE-2021-28041 7.1 / 0.003 7.13 CVE-2021-41617 7.0 / 0.003 7.03 CVE-2023-51767 7.0 / <0.001 7.00 CVE-2016-20012 5.3 / 0.146 6.76 affected by drives one patch action each 23 nodes, 22 edges. Score = CVSS + 10 x EPSS + 5 x KEV + 2 x ransomware. No CVE here is in CISA KEV, so the graph has no KEV node. Highlighted: the top three by fused score. Simulated network, doctoral coursework.
C.2 Redrawn from the Phase 3 notebook run: 23 nodes, 22 edges. Hover or focus a CVE to trace its chain; the matching table row lights up too.

How to read it

Each CVE is scored with a formula a defender can check by hand:

CVSS + 10·EPSS + 5·[KEV] + 2·[ransomware]

Severity says how bad a flaw could be. EPSS says how likely anyone is to use it. Weighting them equally lets a moderate flaw that attackers actually exploit outrank a critical one that nobody touches. The table below lets you watch that happen.

In plain English: the flaw that sounds worst is not always the most urgent. Ranking by how likely attackers are to actually use a flaw changes the order. Press the two buttons to watch the list re-sort.

OpenSSH 8.4p1, top ten CVEs by fused score. Phase 3 notebook run, doctoral coursework. KEV: none listed.
#CVECVSSEPSSKEVFused score
1CVE-2023-384089.80.644no16.24
2CVE-2025-264656.80.625no13.05
3CVE-2023-487955.90.542no11.32
4CVE-2008-38449.30.027no9.57
5CVE-2023-513856.50.172no8.22
6CVE-2026-353857.50.001no7.51
7CVE-2021-280417.10.003no7.13
8CVE-2021-416177.00.003no7.03
9CVE-2023-517677.0<0.001no7.00
10CVE-2016-200125.30.146no6.76

Sorted by CVSS alone, CVE-2008-3844 (9.3) sits second and CVE-2025-26465 (6.8) sits seventh. Fused, they swap order, because one has an EPSS of 0.62 and the other 0.03. That swap is the whole argument.

Breakwater in full

Exhibit ESoftware I built

Six builds, each with the security design written down before the code

In plain English: software I wrote, with one safety feature in each that you could check.

Inventory of software builds with status and one security control each
ItemWhat it isStateOne control worth checking
PreppaA two-sided home-cooked food marketplace on Expo, Supabase and Stripe Connect, with 225 versioned migrations and 41 Edge Functions.Pre-launchRow Level Security checked by regression tests in CI
CAC North AmericaOrganization site and admin console for a regional church body.LiveAdmin checked on the server, not just in middleware
Church websitesTwo congregation sites with staff admin panels, giving and a small store.LiveSignature-verified Stripe webhooks; honeypot on public forms
BagslyA fintech savings app with typed vaults and bank linking.In development, privateMoney moves only inside 42 server functions that verify the session first
HoWzA private automation and operations platform on my own hardware.Daily use, privateEncrypted, signed backups and a leak guard on every commit
Brand sitesHand-written static sites for Cyntraix, HoWz Studios and WealthDJ.LiveNo backend and no stored form data

Client engagements are not listed. Repositories that hold private data or move money stay private; for those, the case studies describe the design instead of linking code. Case studies

Exhibit FThe written record

Preprints, essays and a paper in preparation

In plain English: what I have written and posted publicly.

24
SSRN preprints, 2024 to 2026, listed on ORCID
1
ACM-format paper in preparation, on Breakwater

SSRN is a preprint repository, not a peer-reviewed journal. The count says I write; it does not say anyone refereed it.

Limits of this report. The lab is two small machines at home, not an enterprise. Breakwater is a simulated network. Both are labeled that way wherever they appear, and neither is presented as client work. The six key findings these exhibits support are on the first page.