Skip to content
~/mandrakis

cat ./about

About

Vassilis Mandrakis

I'm Vassilis Mandrakis. I run information security for the University of Western Macedonia in Greece, where I designed and built the SOC in-house rather than buying a managed stack. I'm now systematically moving from defensive practice to red team work — CRTO in progress, OSEP next.

My path here took the long route. I started as a web developer in the late '90s, building corporate sites and applications. Then came seventeen years inside the Ministry of Education — teaching Computer Science, programming, and network administration in high schools, and keeping the IT infrastructure of schools across the Corfu region running. In 2021 I moved into the CISO seat at the University of Western Macedonia. Throughout all of it, the curiosity that pushed me as a student to find a critical authentication flaw in Piraeus Bank's first e-banking platform — a hidden navigation element passing the account number as a GET parameter, which granted access to any account — never went away. I reported it. The instinct just compounded into a career.

On the operational side, I designed and operate a custom SOC stack rather than a vendor product. The core is Wazuh, integrated through a custom Python layer with MISP threat intelligence and CrowdSec community reputation data, extended with a separate node feeding deduplicated decisions while preserving their original TTL. The integration extracts observables from alerts, enriches and scores them, and feeds custom detection rules that drive automated firewall-level blocking through active response — all dashboarded in OpenSearch. Most of what I write here about detection engineering comes from running and iterating on that stack day to day.

In parallel, I'm completing an M.Sc. in Computer & Network Security at the Open University of Cyprus, with my attention firmly on the offensive/defensive crossover — the part where understanding the defender deeply makes you a sharper attacker, and vice versa.

Outside formal work, I run my own infrastructure: self-hosted services, experimentation with LoRaWAN through a self-managed ChirpStack server, and controlled lab environments built on aged personal domains for red team tradecraft research. Hands-on infrastructure has always been where I learn fastest.

Where this is heading: a remote red team operator role within the EU or US. I'm deliberately choosing depth of specialisation over collecting certifications for their own sake — the goal is to be genuinely good at the craft, not to pass a filter. If that's the kind of person your team is looking for, get in touch.

speaking & writing

Talks, guest posts, and external publications will be listed here.