Founder · OSINT Intelligence LLC

GalmxCybersecurity Developer & OSINT Researcher

Defensive security practitioner, OSINT researcher, and infrastructure operator building practical tools for threat monitoring and incident investigation.

Summary

Professional Summary

Galmx is a cybersecurity developer and the founder of OSINT Intelligence LLC. He builds practical tools and infrastructure for defensive security, OSINT research, network monitoring, threat intelligence, incident investigation, and security automation. Hands-on experience includes operating honeypots, reviewing malicious activity, managing Linux servers, analyzing network alerts, securing VPN infrastructure, building web applications, and developing security-focused software.

About

About Galmx

Based in Lafayette, Indiana, Galmx works across the intersection of defensive security and software engineering — operating internet-facing security sensors, investigating suspicious authentication activity, and turning raw log data into readable incident reports. Independent study spans networking, Linux security, SOC operations, OSINT, threat intelligence, incident response, and secure development, alongside hands-on labs through TryHackMe.

  • Hands-on defensive security experience
  • Practical Linux and network administration
  • Ability to turn security events into understandable reports
  • Security-focused application development
  • Independent troubleshooting and research
  • Founder-level project ownership
  • Understanding of both technical and business requirements
  • Ability to design tools for real operational workflows
  • Experience maintaining internet-facing services

Certifications

Certifications

Completed certifications are separated from certifications currently in progress or planned.

Completed

  • Google Cybersecurity Professional CertificateCoursera / Google

In Progress / Planned

  • Cisco CCNACurrently studying
  • CompTIA Security+Planned
  • Blue-team training (continuing education)
  • DoD-related certification (future goal)

Education

Education & Current Learning

  • Google Cybersecurity Professional Certificate
  • TryHackMe hands-on cybersecurity labs
  • Independent study: networking, Linux security, SOC operations, OSINT, threat intelligence, incident response, secure development
  • Exploring additional cybersecurity education through Ivy Tech

Skills

Technical Skills

Security & SOC

Security monitoringLog analysisAlert triageIncident investigationIOC enrichmentThreat intelligenceOSINT researchHoneypot operationBrute-force investigationAttack-pattern analysisVulnerability and exposure managementExternal attack-surface monitoringDefensive security automationSecurity reportingAbuse reportingBasic malware and adversary behavior analysis

Networking & Infrastructure

TCP/IPDNSNATFirewallsLinux networkingOpenVPNVPN deployment & troubleshootingNetwork traffic analysisSuricata IDSFail2BanSSH hardeningnftables / iptablesDebian Linux server administrationDockerVPS deploymentReverse proxiesService monitoringDDoS alerting & responseMTU and throughput troubleshooting

Programming & Development

PythonJavaScriptNode.jsExpress.jsTypeScriptRustC++BashHTML / CSSEJSREST APIsMongoDBGit / GitHubSocket.IOWebRTCAuthentication & authorizationBackground jobsAutomated reportingCLI application development

Tools & Platforms

LinuxKali LinuxWindows 11macOSGitHubVS CodeDockerMongoDBCowrieSuricataFail2BanOpenVPNWiresharkNmapDiscord APIsHostingerVPS infrastructure

Projects

Featured Projects

Filter by category and status. Status labels reflect actual project state — nothing is marked Production or Completed without evidence.

Category:
Status:

Sentinel01 SSH Honeypot & Threat Monitoring

Operational
Security & SOCInfrastructure

An authorized, Debian-based defensive monitoring environment using Cowrie, Suricata, Fail2Ban, and Docker to observe and analyze SSH brute-force and post-authentication attacker activity.

  • Monitored SSH brute-force and post-authentication activity
  • Investigated successful weak-credential honeypot sessions
  • Analyzed attacker commands, reconnaissance behavior, source networks, and shared tactics
  • Correlated related incidents into a broader campaign

Authorized honeypot used strictly for defensive research. Live infrastructure details are not disclosed.

OI-CAMP-2026-001 Threat Campaign Analysis

Completed
Security & SOCOSINT

A campaign-level investigation correlating multiple malicious SSH sessions based on shared tactics, commands, reconnaissance behavior, and infrastructure patterns.

  • Incident timelines
  • Indicators of compromise
  • Source-network context
  • Tactics and observed behavior

OSINT Intelligence Security Platform

Active Development
Security & SOCOSINTWeb Development

A platform for external attack-surface monitoring, vulnerability tracking, and client-facing security reporting under active development by OSINT Intelligence LLC.

  • External attack-surface monitoring
  • Vulnerability and exposure tracking
  • Security findings
  • Tenant and client separation

Platform and client portal are under active development; unfinished features are not represented as deployed.

Wraith OSINT & Reconnaissance CLI

Active Development
OSINTAutomation

A command-line OSINT tool for authorized investigations and data collection, built around modular information gathering and structured reporting.

  • Modular information gathering
  • Structured investigation workflows
  • Local evidence storage
  • JSON, CSV, and PDF reporting

Built for authorized investigations only; does not imply unauthorized or guaranteed access to private data.

AegisNet Network Security Analyzer

Planned
Security & SOCInfrastructure

Concept and architecture for a modular network-security analysis tool focused on visibility, findings, and remediation guidance.

  • Network visibility
  • Security findings
  • Plugin-based analysis
  • Clear remediation guidance

Universal Log Investigator

Active Development
Security & SOCAutomation

A SOC-focused application for normalizing and analyzing logs from multiple sources to support investigation workflows.

  • Normalize log formats
  • Identify suspicious activity
  • Support investigation workflows
  • Generate readable security findings

Frosty VPN Infrastructure

Operational
Infrastructure

Private OpenVPN infrastructure deployed and managed across multiple server locations, covering configuration, hardening, and performance troubleshooting.

  • OpenVPN configuration
  • Key and client profile management
  • NAT and firewall rules
  • MTU troubleshooting

Private network infrastructure administration and defensive networking — not an anonymity or abuse service.

Social Media Web Application

Completed
Web Development

A production-oriented Node.js, Express, EJS, MongoDB, Socket.IO, and WebRTC social platform with real-time messaging and calling.

  • User authentication, profiles, and feeds
  • Private accounts and follow requests
  • Multi-image posts and expiring stories with view tracking
  • Close Friends visibility and post visibility controls

Discord Server Protection Platform

Active Development
Security & SOCAutomation

A Node.js and TypeScript security bot with a web dashboard for anti-nuke, anti-raid, and permission auditing.

  • Anti-nuke monitoring
  • Automatic lockdown
  • Anti-raid controls
  • New-account screening

DDoS Monitoring & Discord Alerting

Active Development
Security & SOCAutomation

Infrastructure concepts and scripts for detecting abnormal network traffic and delivering real-time attack notifications.

  • Traffic rate and packets-per-second monitoring
  • Estimated bandwidth reporting
  • Attack duration tracking
  • Possible vector identification

Home-Lab & Small-Business Server Design

Planned
Infrastructure

Planned server and NAS deployments for small-business environments, covering sizing, storage, and continuity planning.

  • Workload assessment and server sizing
  • Storage planning
  • RAID and backup considerations
  • Network segmentation

Discord, Email & Operational Automation

Active Development
Automation

Integrations and workflows connecting Discord bots, webhooks, and email events to infrastructure and security-event reporting.

  • Discord bots and webhooks
  • Server alerts
  • Email-event notifications
  • Workflow automation

Security Research

Security Research & Incident Reports

Authorized defensive research: honeypot operation, attacker behavior analysis, and campaign-level threat intelligence.

Sentinel01 SSH Honeypot & Threat Monitoring

Operational

An authorized, Debian-based defensive monitoring environment using Cowrie, Suricata, Fail2Ban, and Docker to observe and analyze SSH brute-force and post-authentication attacker activity.

  • Monitored SSH brute-force and post-authentication activity
  • Investigated successful weak-credential honeypot sessions
  • Analyzed attacker commands, reconnaissance behavior, source networks, and shared tactics
  • Correlated related incidents into a broader campaign
  • Produced structured incident reports and public-facing security writeups
  • Submitted appropriate abuse reports
  • Integrated Discord notifications for operational alerts

Authorized honeypot used strictly for defensive research. Live infrastructure details are not disclosed.

OI-CAMP-2026-001 Threat Campaign Analysis

Completed

A campaign-level investigation correlating multiple malicious SSH sessions based on shared tactics, commands, reconnaissance behavior, and infrastructure patterns.

  • Incident timelines
  • Indicators of compromise
  • Source-network context
  • Tactics and observed behavior
  • Risk analysis
  • Defensive recommendations
  • Technical reports

Business & Infrastructure

Business & Infrastructure Experience

OSINT Intelligence LLC

Founder & Cybersecurity Developer

  • Founded and operate an Indiana cybersecurity and OSINT company.
  • Develop security, OSINT, threat-intelligence, and incident-analysis tools.
  • Operate defensive monitoring infrastructure and internet-facing security sensors.
  • Investigate suspicious authentication attempts and post-compromise behavior.
  • Produce technical incident reports, campaign summaries, and remediation guidance.
  • Manage Linux servers, databases, web applications, domains, email systems, and production services.
  • Design future client portals, security reporting systems, and recurring security services.
  • Evaluate projects according to client value, security risk reduction, operational efficiency, and revenue potential.

Galmx is based in Lafayette, Indiana, United States.

Contact

Contact Me

Have a project, security question, or opportunity to discuss? Send a message below.