Skip to content
View solomonneas's full-sized avatar

Sponsoring

@openclaw

Block or report solomonneas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
solomonneas/README.md

Yellow ๐Ÿ‘‹, I'm Solomon

I'm a Network & Systems Engineer and teaching lab aid in Tampa, FL, working where cybersecurity, network observability, and AI infrastructure meet. I build SOC tooling, MCP servers, and multi-agent workflows that run on real production gear, not toy demos, and I write about it at solomonneas.dev/blog.

  • US flag US based in Tampa, FL, near the beach.
  • ๐Ÿ‘จโ€๐Ÿ‘ง Father, retired chef of 17 years, OSS contributor, and beach lover when I'm not on a screen.
  • ๐Ÿ“œ M.S. Cybersecurity Intelligence & Information Security at the University of South Florida.
  • ๐Ÿ›ก๏ธ Building open-source SOC and threat-intel tooling on bare-metal Proxmox, stitched together with self-hosted n8n.
  • ๐Ÿค– Deep in multi-agent orchestration, MCP servers, and detection engineering.
  • ๐Ÿ—ฃ๏ธ Ask me about Proxmox, network monitoring, MCP servers, OpenClaw, agent orchestration, and open-source SOC.
  • โš™๏ธ Big believer in open source, dogfooding everything, and writing it down so the next person doesn't have to figure it out.
  • ๐Ÿซถ If my work helped you, buy me a coffee or tip on Ko-fi.
  • ๐Ÿ“ซ Reach me at me@solomonneas.dev ยท LinkedIn ยท X

๐Ÿณ Escoffier Labs

Escoffier Labs is my studio for harness-agnostic agent infrastructure, named for the chef who systematized the kitchen brigade. Tools that get your agents into mise en place and keep them there.

Core

  • ๐Ÿšฉ brigade - the flagship. Your agents run loops; Brigade keeps the receipts. Local operator layer for memory, tasks, tools, research, review, and release across every harness.
  • ๐Ÿฆž solos-cookbook - The companion cookbook: opinionated, dogfooded guide to running a 24/7 multi-agent AI stack on bare metal.

Agent ops

  • ๐Ÿช agentpantry - Encrypted, transport-agnostic sync of browser sessions and secrets from your daily driver to the box your agents run on, so they wake up authenticated.
  • ๐Ÿฉบ memory-doctor - Maintenance CLI for the Claude Code and OpenClaw memory systems: status, lint, ingest, compact.
  • ๐Ÿงฐ bootstrap-doctor - Audits and trims oversize OpenClaw prefix files into reference cards via heuristics and LLM judgment.
  • ๐Ÿ›‚ content-guard - Policy-driven content scanning and publish checks that catch secrets, hostnames, and IPs before they leave the machine.
  • ๐Ÿ”” agent-notify - Privacy-first push notifications for AI coding agents to Discord, Telegram, and Signal with zero telemetry.
  • ๐Ÿ›Ž๏ธ cloche - Agent-neutral desktop capture: polished shots with metadata and stable JSON, with an optional MCP server.

Evidence stack

  • ๐Ÿงพ miseledger - Turns scattered AI work history into a local, searchable evidence ledger: SQLite FTS5 search, Markdown export, and Brigade-ready evidence bundles.
  • ๐Ÿ‘ฃ stationtrail - Exports local agent session logs (Codex, Claude Code, OpenClaw, OpenCode, Hermes) to portable JSONL for MiseLedger.
  • ๐ŸŒพ sourceharvest - Exports non-harness sources like notes, chat exports, and issue exports into the same adapter contract.

Other projects I've built and maintain

OpenClaw & Dev Tools

  • ๐Ÿ” code-search-api - Local semantic code search with Ollama embeddings, SQLite, hybrid search, and LLM summaries.
  • ๐Ÿงฉ code-search-mcp - Read-only MCP server and OpenClaw plugin that puts code-search-api in front of any agent.
  • ๐Ÿ“ก upstream-drift - Upstream drift watcher: LLM-summarized diffs of tracked repos with weekly Discord digests.
  • ๐Ÿ“Š usage-tracker - Token usage and cost analytics for OpenClaw sessions across models.
  • ๐Ÿ“š prompt-library - Dual-mode prompt management with browse/copy UI and a REST API for sub-agents.
  • ๐Ÿ–ฅ๏ธ ops-deck-oss - Self-hosted operational dashboard for OpenClaw users: React UI plus a minimal FastAPI sidecar.
  • ๐ŸŽž๏ธ appreels - Agent-neutral demo-video recorder for clean, repeatable product clips.

Security & Threat Intelligence

  • ๐Ÿ›ก๏ธ cyberbrief - AI threat intel briefings with BLUF reports, ATT&CK mapping, and IOC extraction.
  • ๐Ÿ” bro-hunter - Threat hunting for Zeek and Suricata logs with beaconing detection and MITRE mapping.
  • ๐Ÿ”ฌ intel-workbench - Threat intel analysis with ACH matrices, evidence weighting, and STIX export.
  • ๐Ÿ“– hotwash - SOC playbook parser with mermaid diagram generation and Wazuh alert ingestion.
  • ๐Ÿ—๏ธ soc-stack - Full SOC architecture covering MCP servers, detection pipelines, and deployment playbooks.

MCP Servers

  • ๐Ÿง  cortex-mcp - Observable analysis for IOCs, reports, and response actions.
  • ๐Ÿ›ก๏ธ wazuh-mcp - SIEM access for agents, alerts, rules, and decoders.
  • ๐Ÿ”ฌ misp-mcp - Threat intel search, IOC correlation, and STIX/Suricata/CSV export.
  • ๐Ÿ thehive-mcp - Incident response workflows for cases, alerts, tasks, and observables.
  • โš”๏ธ mitre-mcp - MITRE ATT&CK technique mapping, threat group profiling, and detection gap analysis.
  • ๐Ÿ”Ž zeek-mcp - Network monitoring access for connection, DNS, HTTP, and SSL logs.
  • ๐Ÿฆ” suricata-mcp - IDS/IPS workflows for managing rules, querying alerts, and analyzing traffic.
  • ๐Ÿ•ธ๏ธ maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, ASN, and crt.sh.
  • โš™๏ธ n8n-ops-mcp - Ops control for n8n workflows, validation, and execution lifecycle.
  • ๐Ÿ“ฎ postiz-mcp - Postiz social scheduling control with full public-API coverage, env-gated writes, and a 30/hr rate-limit guard.
  • ๐Ÿงฑ adguard-mcp - AdGuard Home control with tools across read, safe-write, and destructive tiers.
  • ๐Ÿ–ฅ๏ธ proxmox-mcp - Proxmox VE control with 12 tools for container/VM lifecycle, snapshots, and backups.
  • ๐Ÿ“ก librenms-mcp - LibreNMS control with 10 tools for device, port, and alert reads plus alert acks.

Network & Infrastructure

  • ๐Ÿ”ญ watchtower - NOC dashboard with interactive topology, L2/L3 views, and LibreNMS/Proxmox integration.
  • ๐Ÿ”Œ portgrid - Switch port visualization for LibreNMS with color-coded views and instant search.
  • ๐Ÿ”’ proxguard - Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts.
  • ๐Ÿงฎ config-diff-explainer - Offline CLI that turns before/after network device configs into operator-ready reports on what changed, what's risky, and how to roll back. 8 vendor parser paths.
  • ๐Ÿ“ถ eero-cli - CLI for the eero mesh API with SMS auth, filtered device listing, and bulk blocking.
  • ๐Ÿง samba-ad-migration - Windows AD to Samba file share migration scripts for Proxmox.

Media Automation

  • ๐ŸŽฌ jellyfin-mcp - Control Jellyfin from LLMs with playback sessions, library scans, user admin, and 20 MCP tools.
  • ๐Ÿ–ผ๏ธ immich-mcp - Browse and search Immich photos, manage albums, recognize people, surface memories, and resolve duplicates.
  • ๐ŸŽž๏ธ reelgrep - Local video search with ffprobe metadata, Whisper transcription, and FTS5 subtitle search.
  • ๐Ÿ” reelgrep-mcp - MCP wrapper for reelgrep with citation-formatted timestamps from your local video library.
  • ๐ŸŽš๏ธ media-cli - Single-file bash CLI for the self-hosted *arr media stack: Sonarr, Radarr, Prowlarr, qBittorrent, and more, locally or over SSH.

Streaming & OBS

  • ๐ŸŽ›๏ธ deckctl - Declarative driver for the Elgato Stream Deck with YAML config and OBS execution.
  • ๐ŸŽฅ obsctl - kubectl-style multi-host wrapper for managing OBS Studio across machines from one CLI.

I'm always open to building, contributing, collaborating, and chatting. Feel free to reach out.

Featured Writing

Pinned Loading

  1. maltego-mcp maltego-mcp Public

    MCP server for authoring Maltego .mtgx graphs and running primitive OSINT lookups (whois/DNS/ASN/crt.sh). Composes with misp-mcp, thehive-mcp, and other security MCPs.

    TypeScript 4 1

  2. solos-cookbook solos-cookbook Public

    How one engineer runs a 24/7 multi-agent AI stack on bare metal. Opinionated. Dogfooded. Broken-and-fixed in production. Tested in service.

    TypeScript 3

  3. intel-workbench intel-workbench Public

    Browser-native ACH workbench for cyber threat intel analysts: weighted Analysis of Competing Hypotheses, MITRE ATT&CK technique tagging, Heuer/Pherson bias checklist, ICD 203 confidence ribbon. Offโ€ฆ

    TypeScript 1

  4. watchtower watchtower Public

    Sยณ Stack โ€” Real-time NOC dashboard for enterprise network monitoring. LibreNMS, Proxmox, InfluxDB, Palo Alto.

    Python 1

  5. escoffier-labs/brigade escoffier-labs/brigade Public

    Brigade CLI: AI agent memory, handoffs, and local guardrails for Codex, Claude Code, OpenCode, Hermes, and OpenClaw.

    Python 25 2

  6. proxguard proxguard Public

    Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts

    TypeScript 2