Computer Science × Infrastructure Security

I build, break, and operate systems to understand how to secure them.

I’m Edoardo Balzano, a University of Turin Computer Science graduate and MSc Cybersecurity student at Politecnico di Torino. My work sits where Linux, containers, networks, and practical attack/defense meet.

Currently in Turin, completing my MSc in Cybersecurity · Open to security and infrastructure opportunities

Animated infrastructure path from exposed traffic through analysis and containerized servicestraffic → analyze → isolate → operatetrafficPCAP / HTTPanalyzetshark + workerisolateDocker networkoperateLinux / Composelive telemetryedge_01container stack

Evidence, not adjectives

Four ways I approach systems

Each claim below points to a project, a lab, or an experience. Select a lens—or read every item with JavaScript disabled.

Security tooling

HTA & JAR analyzer

A modular Python pipeline for feature extraction, heuristic classification, LLM-assisted assessment, CLI use, and functional tests.

  • Python
  • Static analysis
  • Testing
HTA & JAR analyzer

Sabancı coursework · Team

AquaSecure

A simulated water-treatment SCADA environment used to explore Docker isolation and an SQLi → SSRF → unauthorized Modbus write chain.

  • OT / ICS exposure
  • Docker networks
  • Modbus
AquaSecure

National training program

CyberChallenge.IT Finalist

Represented the University of Turin in the 8th edition after hands-on web, binary, crypto, network, and Attack/Defense training.

  • Finalist 2024
  • A/D CTF
  • Team practice

Continuous practice

Hack The Box

Machine and challenge work used to turn reconnaissance, exploitation, and post-exploitation into a repeatable written process.

  • Web
  • Linux
  • Active Directory
Hack The Box

Reasoning trail

Writeups

Technical records of attack paths, including assumptions, failed branches, evidence, and remediation context.

  • Documentation
  • Reproducibility
  • Reflection
Writeups

Self-hosted lab

Raspberry Pi 5 Docker host

A compact environment for containerized services, private access, controlled exposure, upgrades, and troubleshooting.

  • Docker
  • Tailscale
  • Cloudflare Tunnel

Operated service

AFFiNE

A real containerized workload for practicing deployment, persistence, access paths, service upkeep, and recovery thinking.

  • Self-hosting
  • Containers
  • Maintenance

Exploration

Self-hosted AI workloads

OpenClaw is an exploration area for understanding the boundaries and resource demands of local AI workloads—not a claimed production service.

  • OpenClaw
  • Resource isolation
  • Learning

Front-of-House Manager

Il MuMa

Coordinates reservations, suppliers, cash, inventory, team flow, guest experience, and stewardship of an 80+ label wine cellar.

  • Ownership
  • Composure
  • Communication

2025/26 exchange

Sabancı University

Independent study in Istanbul, technical collaboration in English, and adaptation to a new academic and cultural environment.

  • International teamwork
  • English
  • Adaptability

Front of house

Osteria La Cantinella

Built the reliability, pace, and clear communication needed to keep guest-facing operations moving under pressure.

  • Reliability
  • Service
  • Teamwork

Selected work

Security work with systems underneath it

The flagship began as a practical response to Attack/Defense CTF friction. The supporting projects extend that work into malware analysis and OT/ICS exposure.

02

Supporting security project

Smart HTA & JAR analyzer

A Python analyzer for HTA/JAR feature extraction, explainable heuristics and model-assisted context.

A modular pipeline extracts features from HTA and JAR files, applies explainable heuristic rules, and can ask language models for a second assessment. CLI entry points and functional tests make each stage inspectable.

  • Python
  • BeautifulSoup
  • javap
  • Heuristics
  • LLM APIs
  • Tests
View project
03

Sabancı coursework · Collaboration

AquaSecure

A simulated water-treatment SCADA security exercise with Docker isolation and an SQLi → SSRF → Modbus write chain.

The team isolated services with Docker networks and modeled an attack chain from SQL injection to SSRF and an unauthorized Modbus write. It demonstrates applying security concepts to an OT/ICS-shaped environment—not professional industrial-security expertise.

  • Docker networks
  • SCADA simulation
  • SQL injection
  • SSRF
  • Modbus
View project
CTF Hammer traffic view showing classified HTTP request and response conversations
Authentic CTF Hammer capture from the thesis: HTTP conversations classified during a CyberChallenge simulation.

CTF Hammer / architecture

One workflow, explicit boundaries

A site-native redraw of the thesis architecture: capture, queue, analysis, storage, and live presentation are separated so slow work does not block the operator.

Operate

A small lab, treated like infrastructure

A sanitized view of the Raspberry Pi 5 Docker host. Public and private access paths stay separate; domains, addresses, and ports are intentionally omitted.

International experience

Turin → Istanbul

The 2025/26 Sabancı exchange adds independence, English communication, and cross-cultural teamwork to the technical work—including the AquaSecure coursework project.

CyberChallenge.IT Finalist — 8th Edition, 2024

CyberChallenge.IT 2024 finalist certificate issued to Edoardo Balzano Open certificate preview

Verified credential

CyberChallenge.IT Finalist — 8th Edition, 2024

Official certificate of participation as a finalist. No uncertain team placement is claimed.

Issued by
Cybersecurity National Lab · University of Turin
Year
2024
Download original PDF

CyberChallenge.IT Finalist — 8th Edition, 2024

Full preview of the CyberChallenge.IT 2024 certificate

Field notes

Learning in public

Notes capture concepts as I study them; writeups document the reasoning behind practical HTB work. Entries remain in their original language.