Lab
The Lab is an interactive desktop — windows, a taskbar, and a real terminal. On small screens the experience is poor, so I chose not to fake it. Open it on a computer, or use the tools in their regular form:
Go to the tools →// Lab
Double-click (or tap) the icons to open. Try the terminal: `help`.
| Network | 192.168.1.0/24 |
|---|---|
| Broadcast | 192.168.1.255 |
| Netmask | 255.255.255.0 |
| Wildcard | 0.0.0.255 |
| First host | 192.168.1.1 |
| Last host | 192.168.1.254 |
| Usable hosts | 254 |
| Type | Private |
| Binary (network | hosts) | 11000000.10101000.00000001.00001010 |
no hash matches the expected value
⚠ MD5 and SHA-1 are broken for cryptographic purposes — use them for checksums only.
Authentication
Is the IP that delivered the email authorized by the Return-Path domain’s DNS?
Does the domain’s cryptographic signature validate the content?
Does the From domain require and pass aligned authentication?
Signals
Delivery chain (Received)
| # | from | received by | proto | time (UTC) | Δt |
|---|
No Received headers to show.
Summary
| From | — |
|---|---|
| Return-Path | — |
| Reply-To | — |
| To | — |
| Subject | — |
| Date | — |
| Message-ID | — |
⚠ Trust boundary: only the topmost Authentication-Results — written by your own email provider — is trustworthy. Everything below it, including the earliest Received lines, can be forged by the sender.
This tool interprets the verdicts already present in the header; it cannot verify SPF/DKIM by itself — that would require DNS lookups and cryptographic validation at the receiving server.
I’m Daniel Malaco, an Information Security Engineer in Porto, Portugal. Since 2020 I’ve been at Ascendi, designing and operating the security architecture of critical road infrastructure: next-generation firewalls, SIEM, endpoint protection, identity management, threat intelligence and incident response — the full cycle, from designing the control to analysing the event.
I came to security through networks. For several years I designed, installed and commissioned IP networks for metro and rail systems across four countries — the Doha Metro in Qatar, the Santos VLT in Brazil, and the Odense and Bergen light metros in Denmark and Norway. In transport infrastructure a network failure is not an inconvenience: it is a stopped system and thousands of people going nowhere. That is where I learned to design for redundancy, document for whoever comes next, and test everything in staging before touching production.
In 2020 I turned my focus from networks to the people attacking them. At Hardsecure I deployed next-generation firewalls and ran internal penetration tests — finding vulnerabilities before someone else could exploit them — and I carried that offensive perspective into the defensive work I do today. I take it seriously outside working hours too: SANS SEC504, DFIR and ransomware summits, and a CTF won in Lisbon in 2022.
I like building the tools I use: the ones on this site all run in the browser, and at home I keep a homelab with a k3s cluster on Raspberry Pis that serves as the guinea pig for anything I want to try before it gets anywhere near production. This site is part of that — static, bilingual, tracker-free, with its security posture documented and verifiable.
Experience
The essentials are above; the detail of each role lives here, collapsed.
Information Security Engineer · Ascendi Nov 2020 → present
- Context: security of critical road infrastructure, in Portugal.
- Role: designing, deploying and operating information security architecture, handling tasks/incidents in ITSM.
- Technologies: NGFW, AV/EDR, VA, SIEM, IAM, WAF, SEG.
- Outcome: ongoing maintenance of the security of networks, systems and applications through policies and procedures; identifying threats and vulnerabilities and implementing controls to mitigate them via monitoring and security-event analysis.
- External reference: the security infrastructure I helped build was the subject of a Fortinet Customer Story about Ascendi — the article doesn’t name me (it quotes the Head of IT), but I was part of the team behind the work it describes.
Cyber Security Engineer · Hardsecure Feb 2020 → Sep 2020
- Context: next-generation firewall deployment and internal penetration testing.
- Role: installing, configuring and supporting NGFW equipment.
- Technologies: next-generation firewalls (NGFW), network scanning and enumeration.
- Outcome: located vulnerabilities in networks before they could be exploited.
Systems Engineer · Efacec Jan 2019 → Feb 2020
Odense Letbane (Denmark)
- Context: light-metro project in Denmark.
- Role: designing, installing and commissioning IP networks and security.
- Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
- Outcome: the light metro’s IP network and security layer taken from design through commissioning — lab staging, test procedures, and a documented handover to operations.
Bergen D42 (Norway)
- Context: light-metro project in Norway.
- Role: designing, installing and commissioning IP networks and security.
- Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
- Outcome: system requirements turned into documented design, installation and commissioning of the D42 stretch — the technical groundwork for the line entering service.
Junior Consultant · Altran / Network Engineer · Thales Jan 2017 → Dec 2018
Doha Metro (Qatar)
- Context: metro project in Qatar.
- Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
- Technologies: IP networks, BBRS systems, rail/metro environments.
- Outcome: IP networks and the BBRS system (the mobile WiFi that follows the trains) delivered from specification through commissioning, on a metro built from scratch.
VLT Santos (Brazil)
- Context: light rail vehicle (VLT) project in Brazil.
- Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
- Technologies: IP networks, BBRS systems, rail/metro environments.
- Outcome: IP network and BBRS delivered from design through commissioning, adapting the same rail stack to an urban light-rail system.
Education
- MSc in Electrical and Computers Engineering — FEUP, Faculty of Engineering of the University of Porto (2009–2016), specialised in Network and Communication Services.
Certifications
Fortinet (Credly), SANS SEC504 and the summits, Microsoft, CyberDefenders and more — the full list, with current status and independent verification on Credly, lives on its own page: Certifications.
ATT&CK coverage
The MITRE ATT&CK techniques I cover defensively, tactic by tactic, with the tool or experience behind each one — the same résumé, in the industry’s native language: ATT&CK heatmap.
Skills
| Area | Detail |
|---|---|
| Frameworks | MITRE ATT&CK, CIS benchmarks & controls, CISA CPG, OWASP Top 10, ISO 27001 |
| Perimeter | NGFW, WAF, Security Email Gateway (SEG) |
| Endpoint | Antivirus (AV), Endpoint Detection & Response (EDR) |
| Identity | IAM, Active Directory |
| Detection & response | SIEM, vulnerability assessment (VA), penetration testing |
| Resilience | Business Continuity Planning (BCP) |
| Languages | Python, Bash, PowerShell, Golang, C/C++ |
| Platforms | Linux, Windows, AWS, Azure, Rapid7 InsightVM, ServiceNow |
Applied frameworks
The frameworks below show up in the work as tools, not as goals. I use them to structure decisions, prioritise controls, and speak the same language as auditors, vendors and regulators. The table says where each one comes in and at what depth — none of them is explained here.
| Framework | Where it comes into the work | Depth |
|---|---|---|
| ISO 27001 | Reference for security policies and procedures, and for organising technical controls by domain. | Reference |
| NIS2 | Regulatory context of the sector I work in — critical transport infrastructure; it informs control and reporting priorities. | Context |
| CIS Controls & Benchmarks | Baseline for hardening systems and network equipment, and a reference when checking configurations. | Applied |
| CISA CPG | Point of comparison for prioritising baseline controls in critical infrastructure. | Reference |
| OWASP Top 10 | Common vocabulary for classifying findings from vulnerability assessment and internal testing, and for tuning WAF rules. | Applied |
| MITRE ATT&CK | Mapping detection coverage and structuring incident analysis — technique by technique in the heatmap. | Applied |
On the depth column. Applied — in regular use, in controls I operate. Reference — consulted during design and prioritisation, with no formal process attached. Context — the sector’s regulatory backdrop, not a programme I run. No row implies certification, formal audit or declared compliance: it is only where the framework comes into the work.
Up next:
[ ] Star catalog: automatic sync via an authenticated GitHub API
(github-stars is private; catalog.json is hand-vendored into
content/ for now)
Then, backend tools (see dynamic/PLAN.md):
[ ] DNS lookup (A, AAAA, MX, TXT, NS…)
[ ] Domain and IP whois
[ ] Security headers of third-party sites
[ ] IP blacklist checks
The tools in this Lab run 100% in your browser; the two that
talk to the Worker (pwned, mirror) are flagged with
“requires server” on the Tools page.