I'm an open-source software developer and Network & Systems Engineer in Tampa, FL, working where cybersecurity, network observability, and AI infrastructure meet. I build SOC tooling, MCP servers, and multi-agent workflows that run on real production gear, not toy demos, and I write about it at solomonneas.dev/blog.
US based in Tampa, FL, near the beach.
- π¨βπ§ Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
- π M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
- π‘οΈ Building open-source SOC and threat-intel tooling on bare-metal Proxmox, stitched together with self-hosted n8n.
- π€ Deep in multi-agent orchestration, MCP servers, and detection engineering.
- π£οΈ Ask me about Proxmox, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
- βοΈ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
- π«Ά If my work helped you, buy me a coffee or tip on Ko-fi.
- π« Reach me at me@solomonneas.dev Β· LinkedIn Β· X
Escoffier Labs is my studio for harness-agnostic agent infrastructure, named for the chef who systematized the kitchen brigade. Tools that get your agents into mise en place and keep them there.
Core
- π© brigade - the flagship. Local operator layer for agent memory, tasks, tools, research, review, and release across every harness.
- π₯ skillet - Agent skills suite: repo audits, bug hunting, security sweeps, publish gates, releases, and memory handoffs.
- π¦ solos-cookbook - Opinionated, dogfooded guide to running a 24/7 multi-agent AI stack on bare metal.
Agent ops
- πͺ agentpantry - Encrypted, transport-agnostic sync of browser sessions and secrets so agents wake up authenticated.
- π©Ί memory-doctor - Maintenance CLI for the Claude Code and OpenClaw memory systems: status, lint, ingest, compact.
- π§° bootstrap-doctor - Audits and trims oversize OpenClaw prefix files into reference cards via heuristics and LLM judgment.
- π content-guard - Policy-driven content scanning that catches secrets, hostnames, and IPs before they leave the machine.
- π agent-notify - Privacy-first push notifications for AI coding agents to Discord, Telegram, and Signal with zero telemetry.
- ποΈ cloche - Agent-neutral desktop capture: polished shots with metadata and stable JSON, plus an optional MCP server.
Dev tools
- π code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
- π§© code-search-mcp - Read-only MCP server and OpenClaw plugin that puts code-search-api in front of any agent.
- π usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
- π mise-en-scene - Turns source material into self-contained interactive HTML/SVG technical explainers.
Evidence stack
- π§Ύ miseledger - Turns scattered AI work history into a local, searchable evidence ledger: SQLite FTS5 search, Markdown export, and Brigade-ready evidence bundles.
- π£ stationtrail - Exports local agent session logs (Codex, Claude Code, OpenClaw, OpenCode, Hermes) to portable JSONL for MiseLedger.
- πΎ sourceharvest - Exports non-harness sources like notes, chat exports, and issue exports into the same adapter contract.
Security & Threat Intelligence
- π‘οΈ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
- π vervet - Network threat hunting for Zeek and Suricata logs with explainable per-host risk scoring and MITRE ATT&CK mapping.
- π¬ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
- π hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
- ποΈ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.
MCP Servers
- π§ cortex-mcp - Observable analysis for IOCs, reports, and response actions.
- π‘οΈ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
- π¬ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
- π thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
- βοΈ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
- π zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
- π¦ suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
- πΈοΈ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
- βοΈ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.
- π§± adguard-mcp - AdGuard Home control with tools across read, safe-write, and destructive tiers.
- π₯οΈ proxmox-mcp - Proxmox VE control with 12 tools for container/VM lifecycle, snapshots, and backups.
- π‘ librenms-mcp - LibreNMS control with 10 tools for device, port, and alert reads plus alert acks.
Network & Infrastructure
- π watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
- π portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
- π proxguard - Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts.
- π§ samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.
Media Automation
- π¬ jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.
- πΌοΈ immich-mcp - Browse and search Immich photos, manage albums, recognize people, surface memories, and resolve duplicates.
- ποΈ reelgrep - Local video search with ffprobe metadata, Whisper transcription, and FTS5 subtitle search.
I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.
- π° How I Migrated 6 Servers from VMware to Proxmox and Saved $343K
- π₯οΈ I Migrated Our Entire Infrastructure from Hyper-V to Proxmox
- πΏ Replacing SCCM with FOG Project
- π‘οΈ Building an Open-Source SOC
- π§© I Built 7 MCP Servers for Security Tools. The Protocol Was the Easy Part.
- π‘ A Fiber Cut at 2 PM Taught Me Why I Needed to Build Watchtower
- π 3 Days, 18 Hours: What I Learned at NDG's Proxmox Workshop
- π€ Anthropic Broke My OpenClaw Stack. GPT 5.4 Put It Back Together





