Cybersecurity · open source addict

A place for my cybersecurity stuff.

Hi, I'm Shabran. I'm still learning cybersecurity, honestly more curious than expert. But I like building things that are actually useful and giving them away for free. Right now that's CaseSphere (a simple SOC case management tool) and Brun PAM (browser-based privileged access management). Both open source, both self-hosted, both still very much works in progress

What I build

Two tools, one instinct

Give a team one honest, self-hosted place to see what's happening — instead of stitching that together from spreadsheets and shared passwords.

SOC case management

CaseSphere

Gives your SOC team a single pane of glass to triage alerts, investigate cases, track SLA compliance, and respond faster — with AI-powered analysis built in.

Open Source Self-hostable SIEM Integrations
Suspicious PowerShell executionCritical
Multiple failed MFA attemptsHigh
Unusual outbound trafficMedium
MITRE ATT&CK mapped · SLA 02:14 remaining
recording
admin@core-switch-01:~$ show version
Cisco IOS XE Software, Version 17.09.04a
admin@core-switch-01:~$ sudo useradd svc-monitor
REDACTED — likely password
Privileged access management

Brun PAM

Give your team SSH, RDP, and VNC access through the browser — every session recorded, every password redacted automatically, self-hosted and open source.

Open Source Self-hostable SSH · RDP · VNC
Why open source

Built to be run by you, not rented from me

Self-hosted by default

Your data stays on your own infrastructure — nothing about CaseSphere or Brun PAM requires sending it anywhere else.

Built to be read

Small, readable codebases over clever abstractions. You should be able to open the source and follow what's happening.

No lock-in

Fork it, change it, or walk away. Open source means you're never stuck waiting on someone else's roadmap.

About

Shabran Alkhairi

FocusCybersecurity, mostly breaking things on purpose
ApproachOpen source or it didn't happen
CurrentlyShipping CaseSphere + Brun PAM, powered by coffee

Cybersecurity's my thing, but somewhere along the way I caught the open source bug hard, and now it's basically a personality trait. There's something about shipping a tool that anyone can clone, read, and self-host no paywall, no "book a demo," no gatekeeping that just hits different. CaseSphere and Brun are me scratching my own itch: SOC teams drowning in alerts, engineers sharing root passwords like it's fine. So I built the fix and open-sourced the whole thing.

Wanna buy me a coffee, or just nerd out together?

Either way, I'm down to chat.

Get in touch
Work

Projects

Both are open source and built to be self-hosted — pull the code, read it, run it yourself.

SOC case management

CaseSphere

A single pane of glass for triaging alerts, investigating cases, and tracking SLA compliance — with AI-powered analysis, SIEM integrations, and MITRE ATT&CK mapping built in.

Open Source Self-hostable SIEM Integrations
Suspicious PowerShell executionCritical
Multiple failed MFA attemptsHigh
Unusual outbound trafficMedium
MITRE ATT&CK mapped · SLA 02:14 remaining
recording
admin@core-switch-01:~$ sudo useradd svc-monitor
REDACTED — likely password
Browser → Brun PAM (auth, RBAC, audit) → guacd → device
Privileged access management

Brun PAM

Puts a browser between your engineers and your infrastructure — every session recorded, every password redacted, every connection watched live. Built on Apache Guacamole's proven protocol engine.

Open Source Self-hostable SSH · RDP · VNC
Contact

Let's talk

About CaseSphere, Brun PAM, or anything else you're building.