NOEL.SEC
[SECTOR: ORBIT_0x01 // OPSEC SATELLITE MESH]

        
● TRACKING // LAT: 37°46'N LON: 122°25'W

Noel Mendoza

1st-year BCA student // cybersecurity, systems & OPSEC

↓ scroll to inspect dossier
01 // IDENTITY

About & Focus

I am a first-year Bachelor of Computer Applications (BCA) student passionate about Cybersecurity, Systems Programming, and Defensive Operations. While early in my academic journey, I approach technology from first principles: understanding how applications, memory, and networks actually work before analyzing vulnerabilities.

Currently, I am learning C in university, developing a strong appreciation for low-level systems, alongside explorations in C++ and Java, with active plans to expand into Python and Rust. My focus is on building practical projects and developing a holistic, real-world understanding of the cybersecurity industry as a whole.

On the security front, my interests center on Open Source Intelligence (OSINT), Operational Security (OPSEC), and network traffic analysis. Rather than rushing into black-box scanning tools, I spend my time understanding protocols, inspecting packet captures in Wireshark, and preparing for hands-on labs like TryHackMe and HackTheBox.

[+] Low-Level & Systems Grounding
Building strong programming foundations in C/C++ to understand memory, execution flow, and socket communication from the ground up.
[+] OPSEC & Footprint Defense
Treating privacy and OPSEC as everyday operational hygiene — metadata elimination, identity compartmentalization, and surface reduction.
[+] Project-Driven Curiosity
Learning through hands-on builds, technical writeups, and continuous exploration of enterprise cybersecurity domains.
02 // RESEARCH & WRITEUPS

Selected Projects

OSINT OPSEC AUDIT WRITEUP

OSINT Self-Audit: Digital Footprint Mapping & Lockdown

An exhaustive investigation of my personal digital exhaust across search engines, data brokers, and breach caches, paired with an actionable reduction protocol.

[+]
Objective & Scope

To measure my passive exposure across open internet channels using adversarial recon methodologies. The scope spanned public domain records, historical username reuse, breached credential hashes, metadata in legacy document uploads, and automated people-search scrapers.

Methodology
  • Username Enumeration: Queried cross-platform handle presence using custom Python scripts and Sherlock/WhatsMyName against 400+ services.
  • Data Aggregator Recon: Audited records across LexisNexis, Whitepages, and FastPeopleSearch to identify phone, address, and relative linkages.
  • Exif & Metadata Inspection: Extracted EXIF geotags and author usernames from archived PDFs and image uploads via ExifTool.
  • Breach Analysis: Cross-referenced historic personal identifiers against HaveIBeenPwned and DeHashed indices to isolate compromised passwords.
Remediation Implemented

Enforced strict compartmentalization: submitted CCPA/opt-out removals across 28 data broker repositories, transitioned accounts to unique email aliases using SimpleLogin, replaced shared usernames with randomized handles, and configured automated Google Dork alerting for new indexations.

RESEARCH ATTRIBUTION THREAT INTEL

Synthetic Persona Research: Attribution & Unmasking Vectors

Constructed an AI-assisted research persona to stress-test correlation mechanisms and understand how synthetic identities leave detectable forensic breadcrumbs.

[+]
Research Context (Non-Deceptive Framing)

Conducted purely for defensive threat intelligence research: modern cyber threat actors and disinfo campaigns heavily leverage AI-generated personas (sockpuppets). To identify them effectively, defenders must understand the technical correlation vectors that give them away.

Persona Architecture

Built a fully contained fictional researcher identity, including synthetic profile imagery generated with latent diffusion, structured backstory timeline, and LLM-assisted linguistic phrasing.

Forensic Vulnerabilities Identified
  • Linguistic Stylometry: Frequency analysis of sentence length, comma cadence, and idiomatic markers revealed telltale AI tokenization patterns.
  • Activity Temporal Mapping: Posting timestamps revealed rigid operational hours inconsistent with the persona's purported timezone.
  • Image Artifacts: Subtle symmetry errors in earlobes, hair borders, and non-repeating background specular highlights detected via frequency domain analysis.
Defensive Takeaway

Identified key heuristics that investigative analysts can apply to unmask automated disinformation and threat actor sockpuppets without relying on platform telemetry.

THREAT INTEL MITRE ATT&CK ANALYSIS

Threat Intel Report: CVE Breakdown & MITRE ATT&CK Mapping

Technical dissection of a critical remote execution vector, mapping exploitation phases to the MITRE matrix with actionable detection rules and system mitigations.

[+]
Executive Summary

A granular threat intelligence teardown investigating exploitation patterns targeting unauthenticated input deserialization in edge services. Traced the campaign lifecycle from initial vulnerability scanning to interactive command-and-control (C2) persistence.

MITRE ATT&CK Matrix Alignment
  • Initial Access (T1190): Exploit Public-Facing Application via crafted HTTP POST payload bypassing front-end WAF inspection.
  • Execution (T1059.004): Unix Shell spawning child process under web daemon UID.
  • Persistence (T1053.003): Scheduled Task / Cron modification writing base64-encoded curl stage-2 payload.
  • Command & Control (T1071.001): Encrypted outbound DNS tunneling beaconing periodically to drop hosts.
Detection Logic & Defenses

Authored Sigma detection rules to flag anomalous child processes spawned by web server daemons (`nginx`/`apache` launching `sh` or `curl`). Provided iptables egress filtering templates to prohibit unauthorized outbound socket connections.

IN PROGRESS UPCOMING LAB

Packet Capture & Protocol Anomaly Analysis

Deep PCAP dissection identifying anomalous TCP flags, unencrypted protocol exfiltration, and beaconing behaviors. Full writeup publishing upon lab conclusion.

[—]
03 // CAPABILITIES

Skills & Learning Track

PROGRAMMING & SYSTEMS [BCA CORE]
  • C Programming University Core
    Pointers, memory management, low-level I/O, data structures.
  • C++ & Java Foundations
    Object-oriented architecture, structured logic, algorithmic problem-solving.
  • Linux Systems & CLI Daily Driver
    Filesystem navigation, permissions, process isolation, shell scripting.
  • Git & Technical Writing Standard
    Version control workflows, Markdown documentation, reproducible code.
CYBERSECURITY & RECON [RESEARCH]
  • OPSEC & Compartmentalization Core Philosophy
    Identity hygiene, metadata stripping, leak prevention, alias management.
  • OSINT & Surface Mapping Methodology
    Digital footprint auditing, passive reconnaissance, data broker removal.
  • Wireshark & Packet Analysis Active Practice
    Dissecting TCP/IP streams, protocol inspection, traffic baselines.
  • Threat Landscape & MITRE Study Track
    Mapping adversary techniques, defensive triage, industry tradecraft.
ROADMAP & LABS [IN PROGRESS]
  • Python & Rust Active Pursuit
    Automation scripting, custom recon tools, memory-safe systems.
  • TryHackMe & HackTheBox Target Platforms
    Hands-on labs, guided learning paths, defensive & CTF challenges.
  • Web Security Fundamentals OWASP Top 10
    Analyzing HTTP headers, injection vectors, and secure app design.
  • Industry Architecture Broad Overview
    Enterprise security operations, SOC roles, and defensive architectures.
04 // CONTACT

Initiate Contact

Looking for an enthusiastic, disciplined security mind?

I am a 1st-year BCA student actively seeking internships, mentorship, junior security analyst roles, or collaborative projects. If you value low-level curiosity, analytical rigor, and an OPSEC-first mindset, let's connect.