Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
Home

Build archive

Projects

Security tools, applied AI systems, and full-stack products. Filter the catalog, inspect the stack, or launch a working demo.

56 projects·53 live demos

56 projects shown

Aegis Intelligence

Independent build

Autonomous AI-powered penetration testing assistant that converts raw reconnaissance data into structured, actionable threat intelligence in real time. Ingests outputs from Nmap and Gobuster, performs live OSINT enrichment, and automatically maps potential vulnerabilities, misconfigurations, and attack paths.

Live buildGenerative AIOSINT

Aegis SOC Analyst

Independent build

Production-grade SOC platform built on Next.js 16, Prisma, and PostgreSQL that normalizes telemetry from firewall, cloud, Active Directory, Linux, and EDR sources into a single event schema, correlates it with MITRE ATT&CK detection rules, and promotes related alerts into scored incidents. An AI analyst layer writes the attack narrative, severity rationale, and containment recommendations, and a threat-hunting console runs a parsed query language against the event store.

Live buildSIEMDetection Engineering

Flight Tracker

Independent build

Real-time flight intelligence platform engineered with Next.js and React that resolves natural-language queries into canonical flight, airport, and route URLs. Fuses live telemetry from Flightradar24, ADS-B.lol, OpenSky, and adsbdb with a custom flight-phase classification engine, geospatial tracking, Leaflet map visualizations, dynamic airport boards, and fault-tolerant data pipelines.

Live buildFlight TrackerReal-Time Data

Fixr

Independent build

AI-powered troubleshooting tool using text, images, and live camera input to diagnose hardware issues like loose cables, damaged components, overheating, and blinking error patterns, then delivers step-by-step repair guidance instantly.

Live buildGoogle AI StudioComputer Vision

FinSight

Independent build

AI-powered financial intelligence platform that analyzes complex documents, extracts structured evidence, and adds a credit-card intelligence workspace for comparing rewards, fees, spending profiles, and first-year value. Built with FastAPI, React, AWS Bedrock, LandingAI ADE, and explainable recommendation logic.

Live buildFastAPIReact

Airport Operations Simulator

Independent build

AI-powered airport operations simulation platform designed to model airport activity, aircraft movements, gate utilization, operational disruptions, and resource allocation. Simulates evolving airport conditions and uses AI-driven decision support to explore how operational teams can respond to congestion, delays, and unexpected events.

Live buildAISimulation

Khan OS

Independent build

Personal AI operating system that combines multimodal conversation, local utilities, reminders, alarms, calculations, and structured agent planning. It separates intent from execution, exposes tool permissions, latency, and cost, and keeps consequential actions inside an explicit approval flow.

Live buildReact 19TypeScript

Employee Scheduling & Team Management System

Independent build

Comprehensive scheduling platform with real-time updates, shift swapping, and role-based access. Flask + React web app paired with React Native + Firebase mobile app, boosting team coordination by 30%.

Live buildFlaskReact

InterviewAI

Independent build

AI-powered interview preparation platform that analyzes resumes to generate personalized interview questions, simulates realistic timed interviews, and provides multi-dimensional performance feedback with AI-generated improvement suggestions.

Live buildAIResume Analysis

The Forge

Independent build

AI platform that analyzes, creates, and secures legal and financial documents. Highlights contract risks, generates agreements with built-in security checks, and auto-fills US tax forms including nonresident alien forms.

Live buildLLMOCR

Encrypted File Vault

Independent build

Open-source secure file storage prototype with client-side AES encryption, PBKDF2-derived per-user keys, role-based access control, audit logging, S3 presigned URLs, and an admin dashboard.

Live buildAES EncryptionS3

AI Cybersecurity & Financial Analysis Agents

Independent build

Suite of AI-driven agents for detecting cybersecurity threats and analyzing financial market behaviors using ML, predictive modeling, and real-time API data feeds with comprehensive visualization dashboards.

Live buildPythonScikit-learn

NASA Space Apps Challenge

Independent build

Real-time astronaut health monitoring dashboard built during an international hackathon, integrating Flask REST APIs with a dynamic JavaScript frontend for live visualization of vitals and environmental data.

Live buildFlaskREST API

RelapseRadar

Healthcare AI

Streaming data platform that analyzes wellness signals in real time, surfaces evolving risk scores, and delivers empathetic AI coaching for patients while giving counselors a simple triage view.

Live buildPathwayFastAPI

SharePoint Analyzer

Independent build

Enterprise SharePoint security analysis platform that maps users, security groups, files, folders, sharing links, and permissions into a unified access hierarchy. Analyzes permission inheritance and excessive access to identify security risks and simplify SharePoint cleanup, with a planned remediation workflow for creating security groups and automatically applying least-privilege access.

Live buildMicrosoft SharePointMicrosoft Graph

Offboarding Orchestrator

Security Labs

Offboarding workflow model that tracks every access path an identity holds across identity provider, network, cloud keys, tokens, MFA enrolment, non-SSO SaaS, endpoint, and physical badge, computing the residual access window rather than assuming one account disable is sufficient.

Live buildOffboardingIdentity Lifecycle

Xternal

Independent build

Xternal builds production AI systems for operations, marketing, education, and internal service desks. Its work spans custom agents, workflow automation, AI enablement, focused enterprise-platform replacements, and lead-intelligence workflows that turn qualification signals into clear sales priorities.

Live buildAIAI Agents

ThreatMap

Security Labs

Live threat-intelligence visualization that plots inbound attack origins on a world map, streams a feed of enriched IOCs, and ranks the most active malicious source regions.

Live buildThreat IntelOSINT

Automated Java & Python Grading Engine

Independent build

Hybrid grading system that compiles, executes, and evaluates student submissions at scale. Custom Java test harness with Python orchestration, sandboxed environments, and detailed pass/fail reports.

Live buildJavaPython

IT Ticketing Platform

Independent build

IT service management platform for submitting, categorizing, assigning, tracking, and resolving technical support requests. Models real-world service desk workflows while providing centralized visibility into ticket status, priorities, and support operations.

Live buildFull StackITSM

Resume Match

Security Labs

Screening model that evaluates a resume against a role's requirements with alias and adjacent-tool matching, treating required items as gates rather than score contributions, and returning each unmatched requirement as a specific thing to evidence or to build.

Live buildResume AnalysisSkills Matching

TicketFinder

Independent build

Ticket discovery platform designed to simplify finding and comparing event tickets through a centralized search experience. Aggregates ticket information and presents users with relevant event and pricing information in an easy-to-navigate interface.

Live buildReactAPIs

Study Planner

Security Labs

Certification study planner that allocates a finite study budget across exam domains by exam weight, knowledge gap, and retention decay since the last review, projecting readiness at the exam date rather than producing a flat topic checklist.

Live buildSpaced RepetitionCertification Prep

Password Policy Simulator

Security Labs

Policy simulator that evaluates password rules against real cracking economics, modelling how composition requirements and forced rotation reduce effective entropy, how hash choice moves guess rate by orders of magnitude, and what share of an organisation falls in a 24-hour offline attack.

Live buildPassword SecurityNIST 800-63B

API Threat Model

Security Labs

API security review model that inventories endpoints and checks each for object-level authorisation on client-supplied ids, function-level authorisation on privileged routes, mass assignment, unauthenticated writes, and unbounded authentication paths.

Live buildAPI SecurityOWASP

SIEM Cost

Security Labs

Log pipeline economics model that routes each telemetry source to index, field-filter, archive, or drop, then reports monthly ingest cost against value-weighted detection coverage and names exactly which detections each saving gives up.

Live buildSIEMLog Engineering

Incident Comms

Security Labs

Incident communication planner that derives severity from which of confidentiality, integrity, and availability are affected at what scale, then computes regulatory notification deadlines separately and orders every audience with the content each one should receive.

Live buildIncident ResponseGDPR

Data Classifier

Security Labs

Sensitive data classifier that pairs each detector with a checksum or a context anchor (Luhn validation for card numbers, label anchoring for record numbers and dates of birth), derives a document classification from the strongest category found, and renders an in-place redacted view.

Live buildData ClassificationPII

Backup Assurance

Security Labs

Backup verification model that tests each system's claimed recovery objectives against reality: interval versus RPO, measured restore duration versus RTO, immutability under a ransomware scenario, and how stale the last successful restore test is.

Live buildBackup & RecoveryRansomware

Kube Guard

Security Labs

Kubernetes admission controller model that evaluates pod specifications against the restricted Pod Security Standard plus operational rules, rendering deny, warn, and pass verdicts with the enforcement and audit-mode difference made explicit.

Live buildKubernetesAdmission Control

MFA Fatigue Detector

Security Labs

Authentication log analyser that detects MFA fatigue attacks from the signature pattern of repeated rejected push prompts ending in an approval, weighted by device enrolment status, source ASN classification, and geographic baseline deviation.

Live buildMFAIdentity Security

Phish Sim

Security Labs

Phishing simulation planner that models click rate, credential submission, and report rate per department across lure difficulty and completed training cycles, foregrounding credential entry on privileged accounts rather than raw click counts.

Live buildSecurity AwarenessPhishing

WAF Rule Lab

Security Labs

Web application firewall rule laboratory that runs attack payloads and legitimate traffic through three rule generations, showing how literal keyword matching is defeated by inline comments and why parameter context is what finally removes the false positives.

Live buildWAFApplication Security

Container Sentinel

Security Labs

Container image auditor that grades base image currency, root execution, added Linux capabilities, layer-embedded secrets, digest pinning, and package CVEs, then renders the admission decision a gate would make.

Live buildContainer SecurityDocker

IAM Drift

Security Labs

Permission drift analyser that compares granted entitlements against 90 days of observed usage per identity, surfacing dormant accounts with live credentials, wildcard grants, IAM self-escalation paths, and the specific permissions safe to remove.

Live buildIAMLeast Privilege

SecretSweep

Security Labs

Repository secret scanner that reports exposure window and blast radius per finding, distinguishing values still in the working tree from values reachable only in pushed history, and drives a rotation-first remediation sequence rather than a history rewrite.

Live buildSecret ScanningGit

TLS Inspector

Security Labs

Transport security grader that evaluates offered protocol versions, cipher suite properties, key type and size, certificate expiry and chain completeness, HSTS strength, and OCSP stapling, producing a letter grade with a named mechanism and fix per finding.

Live buildTLSCryptography

PatchPilot

Security Labs

Vulnerability prioritisation engine that scores findings as likelihood times impact, drawing likelihood from EPSS and known-exploited status and impact from asset exposure and tier, then assigns remediation SLAs and shows how badly a CVSS-only sort misorders the queue.

Live buildVulnerability ManagementEPSS

Ransomware Canary

Security Labs

Behavioural detection model that scores five-second windows of file activity on write volume, write entropy, in-place rename bursts, canary file access, and shadow copy deletion, then triggers containment and reports how many files were lost before it fired.

Live buildRansomwareBehavioural Detection

DNS Sentinel

Security Labs

DNS telemetry analyser that scores queries on label entropy, label length, NXDOMAIN response rate, and per-zone query volume to separate domain-generation algorithms and DNS tunnelling from ordinary resolution, with tunable thresholds.

Live buildDNS SecurityExfiltration

CredGuard

Security Labs

Attack-economics model for credential stuffing that composes rate limiting, account backoff, breached-password screening, risk-based challenges, device fingerprinting, and MFA, quantifying both the takeovers prevented and the legitimate users inconvenienced.

Live buildAccount SecurityCredential Stuffing

Sentinel Rules Studio

Security Labs

Detection authoring and regression workbench that evaluates Sigma-style rules against a labelled event corpus, reporting precision, recall, and per-event outcomes so the cost of broadening a condition is measurable instead of assumed.

Live buildDetection EngineeringSigma

Premier Website

Client Work

Modern corporate website developed for Premier to provide organizational information, services, resources, and a professional digital presence. Focused on creating a maintainable and user-friendly web experience.

Case studyWeb DevelopmentUI/UX

Premier IT Operations Suite

Client Work

Internal IT operations suite that combines a searchable support knowledge base with an auditable technology-history ledger. It centralizes troubleshooting guidance, procedures, infrastructure changes, system context, review status, and institutional knowledge for dependable support and operational decision-making.

Case studyKnowledge ManagementIT Support

Travel Intelligence

Independent build

AI-powered travel intelligence platform that combines flight, destination, transportation, and trip-planning information into a unified experience. Designed to help users research destinations, evaluate travel options, and turn fragmented travel data into personalized recommendations and actionable itineraries.

Live buildAITravel Technology

ZeroTrust Gateway

Independent build

Policy-based access broker that evaluates every request against device posture, geo, MFA status, and resource sensitivity to make an explainable allow, step-up, or deny decision.

Live buildZero TrustAccess Control

DevSecPipeline

Independent build

Shift-left security gate that scans a repository on push for hardcoded secrets, vulnerable dependencies, and injection patterns, then blocks or passes the build with a findings report.

Live buildDevSecOpsSAST

LogLens

Security Labs

Streaming log analytics that establishes a rolling baseline, computes z-scores on event rates, and surfaces statistical anomalies in real time before they become incidents.

Live buildAnomaly DetectionStreaming

CloudGuard

Security Labs

Paste an AWS IAM policy and CloudGuard audits it for wildcard actions, privilege-escalation paths, public exposure, and missing conditions, scoring least-privilege compliance.

Live buildAWSIAM

PortSentry

Security Labs

Simulated reconnaissance tool that sweeps a target host, fingerprints open services and versions, and flags risky exposed ports the way Nmap would in a live engagement.

Live buildNetwork SecurityNmap

SecureAuth

Security Labs

Lightweight identity provider that signs, decodes, and verifies JSON Web Tokens with HMAC-SHA256, demonstrating tamper detection and expiry handling end to end.

Live buildOAuth2JWT

PhishGuard

Security Labs

Paste a raw email and PhishGuard inspects SPF/DKIM alignment, sender spoofing, link domains, and social-engineering language to produce a weighted phishing verdict.

Live buildEmail SecuritySPF/DKIM

SentinelSOC

Security Labs

Real-time SOC console that ingests alerts, correlates them against MITRE ATT&CK techniques, scores severity, and drives an analyst triage queue with acknowledge/escalate workflows.

Live buildSIEMMITRE ATT&CK

Network Intrusion Detection System

Independent build

Snort-based IDS deployed to monitor and analyze simulated network traffic, identifying malicious patterns using Wireshark for traffic analysis and Python for automation and alert handling.

Live buildSnortWireshark

Patient Summary Assistant

Healthcare AI

Streams patient documents and generates specialist-tailored summaries with citation-level traceability. Updates instantly when new records arrive, helping clinicians focus on decisions instead of record gathering.

Live buildPathwayFastAPI

BloomGuard

Healthcare AI

Full-stack maternal health prototype supporting symptom logging, AI-driven risk assessment, personalized trimester guidance, and a real-time clinician dashboard that sorts patients by risk level.

Live buildFastAPINext.js 16