blue-team / cloud-security / systems

HAITAO ZHENG
(TAO)

Cyber Security & Privacy | Systems & Infrastructure Engineering

local / portfolio console
Haitao Zheng

active file

live

Security engineering portfolio

Compact work around logs, IOCs, AWS, and reviewable engineering.

latest cfn-lint PR #4566
stack Python / Java / C / SQL

Selected work

Projects.

Small tools and practical work around logs, IOCs, cloud security, and detection engineering.

View GitHub

Swipe sideways to scan project cards →

Open SourceCloudFormationPR

cfn-lint contribution

A focused upstream fix for a false positive in the legacy Elasticsearch domain instance type enum.

Issue`AWS::Elasticsearch::Domain` was checked with OpenSearch `.search` instance names.
PatchRestore `.elasticsearch` values for the legacy resource and add a regression fixture.
View PR
PythonIOCBlue Team

Sentinel-IOC-Toolkit

A lightweight tool for extracting IOCs from logs and preparing them for security analysis workflows.

WorkflowCollect messy text, extract indicators, remove duplicates, and make output easier to review.
NextAdd tests, sample logs, clearer CLI docs, and CSV/JSON exports.
Open on GitHub
HTMLDesignPortfolio

tzheng.dev

This personal site: a compact portfolio for education, projects, notes, and security-focused engineering work.

GoalKeep the site fast and simple while making the information architecture more useful.
DirectionAdd short project writeups and research notes over time.
Open repository

Education.

A rigorous foundation in engineering and privacy.

H-BRS

University of Bonn-Rhein-Sieg (H-BRS)

Germany · University of Applied Sciences
Oct 2025 – Present

B.Sc. Cyber Security & Privacy

Academic Focus: Building strong engineering foundations across Java Programming, Linux environments, Networking Protocols, SQL-based Database Systems, Mathematics, and Technische Informatik (Digital & Analog Electronics).

Privacy & Security: Focused study of the General Data Protection Regulation (GDPR), Privacy-by-Design principles, and infrastructure-oriented cybersecurity within modern European regulatory environments.

Technical Coursework & Projects: Actively working on systems-focused programming assignments and technical projects involving Java, C, SQL, networking, and Linux-based environments.

FHM

FHM University of Applied Sciences

Bielefeld, Germany
Dec 2024 – June 2025

Accelerated University Transition & FSP

Academic Acceleration: Successfully completed the German university preparatory pathway (Feststellungsprüfung / FSP) — the national Abitur-equivalent — within a single high-intensity semester.

Language Achievement: Attained certified German C1 Proficiency within the same 6-month timeframe of academic immersion.

Harvard

Harvard University

CS50x
2024

Computer Science Foundations Certified Completion

Engineering Foundations: Successfully completed Harvard’s CS50x curriculum through intensive project-based coursework focused on algorithms, data structures, computational problem solving, low-level memory concepts in C, Python programming, SQL, and foundational web development.

Final Project: Completed a final independent programming project demonstrating structured software design, debugging workflows, and practical problem-solving under self-driven development conditions.

Jimei

Xiamen Jimei Middle School

Sept 2021 – June 2024

High School Diploma Nationally Recognized Provincial Key High School

Academic Background: Completed a rigorous science-focused academic track at an elite institution with a century-long heritage.

Gaokao Achievement: Achieved high-ranking results in the National Higher Education Entrance Examination (Gaokao), qualifying for admission to top-tier undergraduate programs.

Technical Toolkit.

Engineering robust and secure environments.

Systems & Infrastructure

Hands-on knowledge of Linux environments, networking fundamentals, and secure VPN tunneling.

Cloud Research

Currently researching Cloud Infrastructure and server hardening to optimize infrastructure resilience.

Deployment

Expanding expertise in Cloudflare-based deployment workflows and edge infrastructure.

Development

Building competencies across Java, Python, C, and SQL with a focus on security-conscious programming.

AI-Enhanced Workflows

Leveraging LLM-assisted engineering and modern AI tooling to enhance development productivity and technical research.

Research log

Notes.

Short notes from projects, labs, and open-source work. Designed as a quiet, expandable writing system.

Research log2026-06

Reading CloudTrail logs by hand

A short note about failed console logins, root account events, IAM changes, and why small log samples are useful before using bigger tools.

Read note
AWSlogs
Open source2026-06

What makes a small PR good

A practical reminder: reproduce the bug, keep the patch small, add one test or fixture, and explain what was verified.

Read note
open-sourceworkflow
Blue team2026-06

IOC extraction as a first blue-team tool

Notes on parsing IPs, URLs, and hashes from text, and why the output format matters for later investigation.

Read note
IOCPython

Languages.

English

C2 Professional.

German

C1 Advanced Academic.

Mandarin

Native.

Hokkien

Fluent.

Japanese

A2 Elementary.

Personal Interests.

Photography

Dedicated enthusiast using a Nikon D750. Focused on Portrait, Humanistic, and Landscape photography.

Athletics & Fitness

Passionate about Football, Skateboarding, Basketball, Badminton, and Volleyball. Consistent Strength Training.

Global Insight & Cycling

Enthusiast for recreational off-road cycling. Interested in Geopolitics, Financial Investment, and global markets.