Lab

[ The Lab wants a bigger screen ]

The Lab is an interactive desktop — windows, a taskbar, and a real terminal. On small screens the experience is poor, so I chose not to fake it. Open it on a computer, or use the tools in their regular form:

Go to the tools →

// Lab

Double-click (or tap) the icons to open. Try the terminal: `help`.

>_ terminal
~$
⌗ Subnet calculator
Network192.168.1.0/24
Broadcast192.168.1.255
Netmask255.255.255.0
Wildcard0.0.0.255
First host192.168.1.1
Last host192.168.1.254
Usable hosts254
TypePrivate
Binary (network | hosts)11000000.10101000.00000001.00001010
# Hashes
no file chosen

⚠ MD5 and SHA-1 are broken for cryptographic purposes — use them for checksums only.

⇄ Encoder / Decoder
⚿ Password generator
@ Email header analyzer

In Gmail: ⋮ → “Show original”. In Outlook: File → Properties → “Internet headers”. Paste the full text here.

☰ about.md

I’m Daniel Malaco, an Information Security Engineer in Porto, Portugal. Since 2020 I’ve been at Ascendi, designing and operating the security architecture of critical road infrastructure: next-generation firewalls, SIEM, endpoint protection, identity management, threat intelligence and incident response — the full cycle, from designing the control to analysing the event.

I came to security through networks. For several years I designed, installed and commissioned IP networks for metro and rail systems across four countries — the Doha Metro in Qatar, the Santos VLT in Brazil, and the Odense and Bergen light metros in Denmark and Norway. In transport infrastructure a network failure is not an inconvenience: it is a stopped system and thousands of people going nowhere. That is where I learned to design for redundancy, document for whoever comes next, and test everything in staging before touching production.

In 2020 I turned my focus from networks to the people attacking them. At Hardsecure I deployed next-generation firewalls and ran internal penetration tests — finding vulnerabilities before someone else could exploit them — and I carried that offensive perspective into the defensive work I do today. I take it seriously outside working hours too: SANS SEC504, DFIR and ransomware summits, and a CTF won in Lisbon in 2022.

I like building the tools I use: the ones on this site all run in the browser, and at home I keep a homelab with a k3s cluster on Raspberry Pis that serves as the guinea pig for anything I want to try before it gets anywhere near production. This site is part of that — static, bilingual, tracker-free, with its security posture documented and verifiable.

Experience

The essentials are above; the detail of each role lives here, collapsed.

Information Security Engineer · Ascendi Nov 2020 → present
  • Context: security of critical road infrastructure, in Portugal.
  • Role: designing, deploying and operating information security architecture, handling tasks/incidents in ITSM.
  • Technologies: NGFW, AV/EDR, VA, SIEM, IAM, WAF, SEG.
  • Outcome: ongoing maintenance of the security of networks, systems and applications through policies and procedures; identifying threats and vulnerabilities and implementing controls to mitigate them via monitoring and security-event analysis.
  • External reference: the security infrastructure I helped build was the subject of a Fortinet Customer Story about Ascendi — the article doesn’t name me (it quotes the Head of IT), but I was part of the team behind the work it describes.
Cyber Security Engineer · Hardsecure Feb 2020 → Sep 2020
  • Context: next-generation firewall deployment and internal penetration testing.
  • Role: installing, configuring and supporting NGFW equipment.
  • Technologies: next-generation firewalls (NGFW), network scanning and enumeration.
  • Outcome: located vulnerabilities in networks before they could be exploited.
Systems Engineer · Efacec Jan 2019 → Feb 2020

Odense Letbane (Denmark)

  • Context: light-metro project in Denmark.
  • Role: designing, installing and commissioning IP networks and security.
  • Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
  • Outcome: the light metro’s IP network and security layer taken from design through commissioning — lab staging, test procedures, and a documented handover to operations.

Bergen D42 (Norway)

  • Context: light-metro project in Norway.
  • Role: designing, installing and commissioning IP networks and security.
  • Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
  • Outcome: system requirements turned into documented design, installation and commissioning of the D42 stretch — the technical groundwork for the line entering service.
Junior Consultant · Altran / Network Engineer · Thales Jan 2017 → Dec 2018

Doha Metro (Qatar)

  • Context: metro project in Qatar.
  • Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
  • Technologies: IP networks, BBRS systems, rail/metro environments.
  • Outcome: IP networks and the BBRS system (the mobile WiFi that follows the trains) delivered from specification through commissioning, on a metro built from scratch.

VLT Santos (Brazil)

  • Context: light rail vehicle (VLT) project in Brazil.
  • Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
  • Technologies: IP networks, BBRS systems, rail/metro environments.
  • Outcome: IP network and BBRS delivered from design through commissioning, adapting the same rail stack to an urban light-rail system.

Education

  • MSc in Electrical and Computers Engineering — FEUP, Faculty of Engineering of the University of Porto (2009–2016), specialised in Network and Communication Services.

Certifications

Fortinet (Credly), SANS SEC504 and the summits, Microsoft, CyberDefenders and more — the full list, with current status and independent verification on Credly, lives on its own page: Certifications.

ATT&CK coverage

The MITRE ATT&CK techniques I cover defensively, tactic by tactic, with the tool or experience behind each one — the same résumé, in the industry’s native language: ATT&CK heatmap.

Skills

Area Detail
Frameworks MITRE ATT&CK, CIS benchmarks & controls, CISA CPG, OWASP Top 10, ISO 27001
Perimeter NGFW, WAF, Security Email Gateway (SEG)
Endpoint Antivirus (AV), Endpoint Detection & Response (EDR)
Identity IAM, Active Directory
Detection & response SIEM, vulnerability assessment (VA), penetration testing
Resilience Business Continuity Planning (BCP)
Languages Python, Bash, PowerShell, Golang, C/C++
Platforms Linux, Windows, AWS, Azure, Rapid7 InsightVM, ServiceNow

Applied frameworks

The frameworks below show up in the work as tools, not as goals. I use them to structure decisions, prioritise controls, and speak the same language as auditors, vendors and regulators. The table says where each one comes in and at what depth — none of them is explained here.

Framework Where it comes into the work Depth
ISO 27001 Reference for security policies and procedures, and for organising technical controls by domain. Reference
NIS2 Regulatory context of the sector I work in — critical transport infrastructure; it informs control and reporting priorities. Context
CIS Controls & Benchmarks Baseline for hardening systems and network equipment, and a reference when checking configurations. Applied
CISA CPG Point of comparison for prioritising baseline controls in critical infrastructure. Reference
OWASP Top 10 Common vocabulary for classifying findings from vulnerability assessment and internal testing, and for tuning WAF rules. Applied
MITRE ATT&CK Mapping detection coverage and structuring incident analysis — technique by technique in the heatmap. Applied

On the depth column. Applied — in regular use, in controls I operate. Reference — consulted during design and prioritisation, with no formal process attached. Context — the sector’s regulatory backdrop, not a programme I run. No row implies certification, formal audit or declared compliance: it is only where the framework comes into the work.

⚑ roadmap.txt
Up next:
  [ ] Star catalog: automatic sync via an authenticated GitHub API
      (github-stars is private; catalog.json is hand-vendored into
      content/ for now)

Then, backend tools (see dynamic/PLAN.md):
  [ ] DNS lookup (A, AAAA, MX, TXT, NS…)
  [ ] Domain and IP whois
  [ ] Security headers of third-party sites
  [ ] IP blacklist checks

The tools in this Lab run 100% in your browser; the two that
talk to the Worker (pwned, mirror) are flagged with
“requires server” on the Tools page.
⚡ lab