<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Engineering Projects &amp; Systems Architecture on Brandon Extra | Security &amp; Systems Architecture</title>
    <link>https://brandonextra.com/projects/</link>
    <description>Recent content in Engineering Projects &amp; Systems Architecture on Brandon Extra | Security &amp; Systems Architecture</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://brandonextra.com/projects/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Production Multi-VLAN Network Segmentation &amp; Threat Isolation</title>
      <link>https://brandonextra.com/projects/enterprise-vlan-segmentation/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://brandonextra.com/projects/enterprise-vlan-segmentation/</guid>
      <description>Design and deployment of an enterprise 6-VLAN network topology utilizing virtualized OPNsense, Zenarmor DPI, and default-deny inter-VLAN filtering.</description>
    </item>
    <item>
      <title>Two-Tier Disaster Recovery &amp; Hardened Container Orchestration</title>
      <link>https://brandonextra.com/projects/tier2-disaster-recovery/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://brandonextra.com/projects/tier2-disaster-recovery/</guid>
      <description>Zero-plaintext container deployments paired with a two-tier backup pipeline utilizing local block snapshots and client-side encrypted Backblaze B2 offsite syncs.</description>
    </item>
    <item>
      <title>Hybrid Cloud Perimeter: VPS Reverse-Proxy Shield &amp; Zero-Trust ZTNA</title>
      <link>https://brandonextra.com/projects/hybrid-cloud-edge-defense/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://brandonextra.com/projects/hybrid-cloud-edge-defense/</guid>
      <description>Architecting an obfuscated edge perimeter using a stateless OVHcloud VPS, Caddy Layer 4 filtering, MaxMind GeoIP gating, and a kernel-level WireGuard transit pipe.</description>
    </item>
    <item>
      <title>NOC/SOC Defense: Packet Analysis, Threat Bouncing, and SIEM Telemetry</title>
      <link>https://brandonextra.com/projects/soc-telemetry-packet-analysis/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://brandonextra.com/projects/soc-telemetry-packet-analysis/</guid>
      <description>Implementing a hybrid CrowdSec IPS and log analysis pipeline across edge proxies and hypervisors to detect, analyze, and drop malicious traffic flows.</description>
    </item>
  </channel>
</rss>
