Skip to content
View HugoPBrito's full-sized avatar

Block or report HugoPBrito

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HugoPBrito/README.md

Hello there :))

I'm Hugo, a cloud security and software engineer focused on open-source tools and multi-cloud security.

  • 🔒 Contributed to Prowler through GitHub, Cloudflare, and Microsoft 365 provider integrations.
  • 🛠 Built py-pwsh-session, connecting Python with persistent PowerShell sessions.
  • 🌐 Explore more on my website.
More about my work

GitHub activity

GitHub total contributions, current streak, and longest streak for HugoPBrito

Overview

At Prowler, I worked across the path from cloud-security research to product delivery. That meant studying provider behavior, building checks and integrations, improving APIs and UI, testing edge cases, and supporting releases. The common thread was turning cloud configuration questions into useful findings while making the software dependable for people who run it. My work crossed AWS, Azure, GCP, and Microsoft 365/Entra.

What I do

  • Security research and accuracy: I mapped cloud configuration checks to frameworks such as CIS, ISO/IEC 27001, and HIPAA, and investigated false positives when provider behavior did not match an assumption. I separated GCP KMS rotation checks by compliance requirement, distinguishing a CIS 90-day limit from frameworks that only require rotation to be enabled.
  • Product engineering: I worked on Python integrations, APIs, UI, automated tests, and CI with GitHub Actions, including documentation and release support rather than treating checks as isolated scripts.
  • Open source: I worked in public repositories, collaborated on pull requests, and helped contributors move from an issue to a reviewed change.

Selected work

Open-source tooling

py-pwsh-session grew out of the team’s Microsoft 365 integration. I worked on persistent sessions, command execution, timeouts, and JSON results so Python applications could reuse an authenticated PowerShell process instead of starting one for each query.

What I work with

  • Cloud security: AWS, Azure, GCP, Microsoft 365/Entra, CSPM, and compliance mapping for CIS, ISO/IEC 27001, and HIPAA.
  • Engineering: Python, APIs, UI, testing, PowerShell integrations, and CI/CD with GitHub Actions.

Writing and community

I wrote Running PowerShell from Python about the tradeoffs behind our Microsoft 365 integration, and Certificate-based Microsoft 365 authentication about adapting to MFA enforcement. I also delivered workshops at Hackén 2025 and Hackén 2026, where I appear on the public speaker lists.

Background

I studied computer engineering at the University of Granada and participated in Hackiit, a cybersecurity community centered on hands-on learning, talks, and workshops. My public education page has more background.

Pinned Loading

  1. prowler-cloud/prowler prowler-cloud/prowler Public

    Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

    Python 14.9k 2.4k

  2. prowler-cloud/py-pwsh-session prowler-cloud/py-pwsh-session Public

    Python module to manage persistent PowerShell sessions, with support for command execution, JSON result parsing, and secure error handling.

    Python 5