Skip to content
View andyspyro's full-sized avatar
😀
Focusing
😀
Focusing

Block or report andyspyro

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
andyspyro/README.md

Andy Stein cybersecurity and data analytics profile banner

About

By day, I turn messy data and repetitive processes into dashboards, automations, and workflows people can actually use. Outside of work, I’m finishing my M.S. in Cybersecurity at North Carolina A&T State University and usually have some combination of Python, Burp Suite, a Hack The Box lab, or a microcontroller open nearby.

I’m the kind of person who sees a ten-click process and wants it down to two — or sees a system behaving strangely and needs to know why. That curiosity is what pulled me deeper into cybersecurity: I like understanding how systems work, where they break, and how to make them better.

Proof of Work

Area Demonstrated evidence
Secure Software / AppSec Built a Node.js/Express application with server-side RBAC, CSRF protection, rate limiting, Socket.IO, SQLite, and audit logging.
Offensive Security Completed an authorized chain from enumeration and source review through command injection, service-account access, user compromise, and root privilege escalation.
Embedded Systems Programmed microcontrollers, integrated sensors, designed circuits/schematics, and implemented UART, I²C, and SPI communication across ESP32, Arduino, and Raspberry Pi.
Automation / Data Built Python, Power BI, Excel, and VBA workflows for Windows automation, analytics, reconciliation, validation, and recurring reporting.

Featured Work

Node.js Express SQLite Socket.IO AppSec

Designed and implemented a full-stack Node.js/Express study-room application with authentication, server-side RBAC, CSRF protection, rate limiting, Socket.IO live features, moderated controls, SQLite persistence, and audit logging.

Ethical Hacking Linux Command Injection Privilege Escalation

Completed an authorized end-to-end attack path from source review and service enumeration to command injection, service-account access, user compromise, and Linux privilege escalation to root, documenting the reasoning and validation at each stage.

Microcontrollers Sensors Circuit Design UART / I²C / SPI ESP32 / Arduino / Raspberry Pi

Built and programmed the embedded system end to end: microcontroller code, sensor integration, circuit and schematic design, physical wiring, and UART/I²C/SPI communication across ESP32, Arduino, and Raspberry Pi platforms.

Python Local AI Windows Automation System Diagnostics

Built a multi-version Python local assistant that integrates local models, voice interaction, Windows automation, system diagnostics, research workflows, memory experiments, and visual tooling.

Power BI Excel VBA Reconciliation Reporting Automation

Built and maintained Power BI, Excel, and VBA automation for hiring and vacancy analytics, cross-system reconciliation, workflow tracking, record archiving, data-quality validation, and recurring audit/reporting processes.

IriusRisk STRIDE Data Flow Diagrams Trust Boundaries Security Requirements

Modeled an online-banking application in IriusRisk, created data-flow diagrams and trust boundaries, applied STRIDE, reviewed generated threats, and converted findings into concrete security requirements and mitigations.

More Projects

Security Engineering and Secure Software

Private Data Logging Security Review
Architecture review focused on schema validation, sensitive access, centralized policy enforcement, and auditability.

C and C++ Static Analysis
Flawfinder analysis, 31 findings reviewed, CWE mapping, unsafe function review, memory risk, and command execution risk.

Secure Coding Mini App
Express and MySQL remediation work covering CSRF, SQL injection, XSS, session checks, and safer state changing routes.

OWASP Juice Shop
Semgrep, SonarQube Cloud, SQL injection testing, TypeScript source review, bound query remediation, rebuilding, and retesting.

OWASP WebGoat
SQL injection, CSRF, request analysis, prepared statements, cookies, sessions, and safer request handling.

Offensive Security Labs

Orion
Craft CMS 5.6.16, Python exploit troubleshooting, session state, CSRF, and database credential recovery. Status: in progress.

Valentine
SSH key handling, legacy RSA compatibility, Bash history, tmux investigation, and confirmed user access. Root is not claimed.

CrossFitTwo
OpenBSD enumeration, virtual hosts, curl, ffuf, and password reset account enumeration.

DanglingTree
Windows, IIS, Burp, SmarterMail, log review, credential discovery, and account pivoting. Status: in progress.

HTB Methodology
The process I use for enumeration, testing assumptions, post access checks, privilege escalation, and public note cleanup.

Data, AI, Mobile, Database and Engineering

Android Mobile Prototypes
Kotlin and Jetpack Compose work. The retained Reply Time Tracker includes state, input parsing, list views, and a live timer. I also tested an HR workflow prototype, but I no longer have that original source.

Dating Application Database Team Project
A three person class database project where I serve as the mock project manager while helping coordinate ER and EER design, normalization, SQL work, project phases, and the group submission.

Electrical Engineering & Hardware Build
Built and wired the physical hardware, added the lighting, designed the body, and used Nova as a research tool for embedded systems, sensors, controllers, and technical documentation.

Core Stack

Python · JavaScript / Node.js · SQL / SQLite · VBA · PowerShell · Linux · Burp Suite · Nmap · Power BI · ESP32 / Arduino

All security testing shown here was performed in authorized training environments. Public work excludes credentials, private keys, flags, personal records, employer sensitive data, and anything else that should not be public.

Popular repositories Loading

  1. github-slideshow github-slideshow Public

    A robot powered training repository 🤖

    HTML

  2. Cybersecurity-Portfolio Cybersecurity-Portfolio Public

    Cybersecurity and security engineering portfolio featuring AppSec, offensive security, secure software, automation, systems work, and data analytics.

    HTML

  3. Application-security-labs Application-security-labs Public

    Hands on application security labs covering WebGoat, Juice Shop, SQL injection, XSS, CSRF, Burp Suite, static analysis, remediation, and retesting.

    HTML

  4. Security-engineering-projects Security-engineering-projects Public

    Security engineering portfolio covering secure software design, threat modeling, architecture reviews, database engineering, automation, and technical analysis.

    JavaScript

  5. Offensive-Security-labs Offensive-Security-labs Public

    Authorized offensive security labs covering enumeration, exploitation, post-exploitation, privilege escalation, troubleshooting, and defensive analysis.

  6. andyspyro andyspyro Public