Skip to content
View solomonneas's full-sized avatar

Sponsoring

@openclaw

Block or report solomonneas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
solomonneas/README.md

Yellow πŸ‘‹, I'm Solomon

I'm an open-source software developer and Network & Systems Engineer in Tampa, FL, working where cybersecurity, network observability, and AI infrastructure meet. I build SOC tooling, MCP servers, and multi-agent workflows that run on real production gear, not toy demos, and I write about it at solomonneas.dev/blog.

  • US flag US based in Tampa, FL, near the beach.
  • πŸ‘¨β€πŸ‘§ Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
  • πŸ“œ M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
  • πŸ›‘οΈ Building open-source SOC and threat-intel tooling on bare-metal Proxmox, stitched together with self-hosted n8n.
  • πŸ€– Deep in multi-agent orchestration, MCP servers, and detection engineering.
  • πŸ—£οΈ Ask me about Proxmox, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
  • βš™οΈ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
  • 🫢 If my work helped you, buy me a coffee or tip on Ko-fi.
  • πŸ“« Reach me at me@solomonneas.dev Β· LinkedIn Β· X

🍳 Escoffier Labs

Escoffier Labs is my studio for harness-agnostic agent infrastructure, named for the chef who systematized the kitchen brigade. Tools that get your agents into mise en place and keep them there.

Core

  • 🚩 brigade - the flagship. Local operator layer for agent memory, tasks, tools, research, review, and release across every harness.
  • πŸ₯˜ skillet - Agent skills suite: repo audits, bug hunting, security sweeps, publish gates, releases, and memory handoffs.
  • 🦞 solos-cookbook - Opinionated, dogfooded guide to running a 24/7 multi-agent AI stack on bare metal.

Agent ops

  • πŸͺ agentpantry - Encrypted, transport-agnostic sync of browser sessions and secrets so agents wake up authenticated.
  • 🩺 memory-doctor - Maintenance CLI for the Claude Code and OpenClaw memory systems: status, lint, ingest, compact.
  • 🧰 bootstrap-doctor - Audits and trims oversize OpenClaw prefix files into reference cards via heuristics and LLM judgment.
  • πŸ›‚ content-guard - Policy-driven content scanning that catches secrets, hostnames, and IPs before they leave the machine.
  • πŸ”” agent-notify - Privacy-first push notifications for AI coding agents to Discord, Telegram, and Signal with zero telemetry.
  • πŸ›ŽοΈ cloche - Agent-neutral desktop capture: polished shots with metadata and stable JSON, plus an optional MCP server.

Dev tools

  • πŸ” code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
  • 🧩 code-search-mcp - Read-only MCP server and OpenClaw plugin that puts code-search-api in front of any agent.
  • πŸ“Š usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
  • 🎭 mise-en-scene - Turns source material into self-contained interactive HTML/SVG technical explainers.

Evidence stack

  • 🧾 miseledger - Turns scattered AI work history into a local, searchable evidence ledger: SQLite FTS5 search, Markdown export, and Brigade-ready evidence bundles.
  • πŸ‘£ stationtrail - Exports local agent session logs (Codex, Claude Code, OpenClaw, OpenCode, Hermes) to portable JSONL for MiseLedger.
  • 🌾 sourceharvest - Exports non-harness sources like notes, chat exports, and issue exports into the same adapter contract.

Other projects I've built and maintain

Security & Threat Intelligence

  • πŸ›‘οΈ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
  • πŸ” vervet - Network threat hunting for Zeek and Suricata logs with explainable per-host risk scoring and MITRE ATT&CK mapping.
  • πŸ”¬ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
  • πŸ“– hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
  • πŸ—οΈ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.

MCP Servers

  • 🧠 cortex-mcp - Observable analysis for IOCs, reports, and response actions.
  • πŸ›‘οΈ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
  • πŸ”¬ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
  • 🐝 thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
  • βš”οΈ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
  • πŸ”Ž zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
  • πŸ¦” suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
  • πŸ•ΈοΈ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
  • βš™οΈ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.
  • 🧱 adguard-mcp - AdGuard Home control with tools across read, safe-write, and destructive tiers.
  • πŸ–₯️ proxmox-mcp - Proxmox VE control with 12 tools for container/VM lifecycle, snapshots, and backups.
  • πŸ“‘ librenms-mcp - LibreNMS control with 10 tools for device, port, and alert reads plus alert acks.

Network & Infrastructure

  • πŸ”­ watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
  • πŸ”Œ portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
  • πŸ”’ proxguard - Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts.
  • 🐧 samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.

Media Automation

  • 🎬 jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.
  • πŸ–ΌοΈ immich-mcp - Browse and search Immich photos, manage albums, recognize people, surface memories, and resolve duplicates.
  • 🎞️ reelgrep - Local video search with ffprobe metadata, Whisper transcription, and FTS5 subtitle search.

I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.

Featured Writing

Pinned Loading

  1. maltego-mcp maltego-mcp Public

    MCP server for authoring Maltego .mtgx graphs and running primitive OSINT lookups (whois/DNS/ASN/crt.sh). Composes with misp-mcp, thehive-mcp, and other security MCPs.

    TypeScript 5 1

  2. escoffier-labs/solos-cookbook escoffier-labs/solos-cookbook Public

    How one engineer runs a 24/7 multi-agent AI stack on bare metal. Opinionated. Dogfooded. Broken-and-fixed in production. Tested in service.

    Astro 4

  3. intel-workbench intel-workbench Public

    Browser-native ACH workbench for cyber threat intel analysts: weighted Analysis of Competing Hypotheses, MITRE ATT&CK technique tagging, Heuer/Pherson bias checklist, ICD 203 confidence ribbon. Off…

    TypeScript 1

  4. watchtower watchtower Public

    SΒ³ Stack β€” Real-time NOC dashboard for enterprise network monitoring. LibreNMS, Proxmox, InfluxDB, Palo Alto.

    Python 1

  5. escoffier-labs/brigade escoffier-labs/brigade Public

    Brigade CLI: AI agent memory, handoffs, and local guardrails for Codex, Claude Code, OpenCode, Hermes, and OpenClaw.

    Python 30 2

  6. proxguard proxguard Public

    Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts

    TypeScript 2