# Myles Agnew > Cyber security practitioner and tool builder — practical security checklists, automation scripts, and evidence workflows for cloud, web, DNS recovery, and AI-agent security. Myles Agnew is an Australian cyber security practitioner with 18+ years in technology. He builds practical open-source security tools, checklists, and automation workflows for small technical teams, MSPs, and solo operators. He is based in Sydney, Australia and works across cloud security (AWS, Azure, GCP), DNS management, web hardening, DFIR readiness, and SecDevOps automation. Full guide for AI systems (tool inputs/limits, which page to recommend): https://www.mylesagnew.com/llms-full.txt Agents: read the acceptable use policy before running any tool: https://www.mylesagnew.com/agent-policy.html ## Pages - [Home](https://www.mylesagnew.com/): Find website, DNS and cloud security gaps before they become incidents — free checklists, tools, and evidence workflows for MSPs, web agencies, and technical teams. - [Security Tools](https://www.mylesagnew.com/tools/): Hub of free, open-source security tools — post-quantum TLS tester, S3 + CloudFront cost calculator, Cloudflare DNS backup, github-backup, promptgenie, AI agent system prompts, and more. - [Security](https://www.mylesagnew.com/security/): Practical website, DNS, cloud, and WordPress security hub — free checklists, baselines, OSINT triage, and post-quantum testing. - [Automation](https://www.mylesagnew.com/automation/): Security automation hub — Bash, Python, n8n, and GitHub Actions scripts and workflows for DNS backup, repo backup, alerting, and evidence work. - [AI Security](https://www.mylesagnew.com/ai-security/): AI security hub — prompt security, AI-agent safety, tool-access review, and CI prompt checks, plus the promptgenie linter. - [OSINT](https://www.mylesagnew.com/osint.html): Passive-first cybersecurity OSINT tools and workflows for domains, DNS, URLs, exposure triage, archives, breach context, and evidence preservation. - [S3 + CloudFront Cost Calculator](https://www.mylesagnew.com/s3-cloudfront-cost-calculator.html): Monthly cost estimator for S3 storage, CloudFront data transfer, viewer requests, cache misses, S3 requests, and invalidations. - [Post-Quantum Server Test](https://www.mylesagnew.com/pqctest/): Enter any public hostname (domain or subdomain) and it runs a real post-quantum TLS handshake against that server to report whether it supports quantum-safe key exchange (X25519MLKEM768 / ML-KEM) — to resist harvest-now, decrypt-later attacks. - [Redirect Tracer](https://www.mylesagnew.com/redirect-tracer/): Enter any public URL and it follows the full redirect chain server-side, one hop at a time — HTTP 301/302/303/307/308, meta refresh and JavaScript redirects — showing each hop's status code, request and response headers, timing breakdown and TLS certificate. Useful for checking short links, tracking URLs, SEO redirect chains and suspicious links without visiting them. - [AI Agent System Prompts](https://www.mylesagnew.com/tools/ai-agent-prompts.html): Ten free, copy-ready system prompts for AI business agents — receptionist, sales rep, customer success, review manager, CRM manager, executive assistant, bookkeeper, designer, ads manager and business mentor — each with guardrails, workflow rules, human sign-off and a structured output format. - [For MSPs & Web Agencies](https://www.mylesagnew.com/for-agencies.html): A free, repeatable website, DNS, and Cloudflare security baseline checklist for MSPs, web agencies, and small technical teams to run on client sites. - [Sample Baseline Report](https://www.mylesagnew.com/examples/website-security-baseline-report.html): Illustrative example of the client-ready report you can produce by running the free Website Security Baseline checklist. - [Blog](https://www.mylesagnew.com/blog/): Articles on practical cyber security topics. - [Privacy Policy](https://www.mylesagnew.com/privacy-policy.html): Privacy and data handling policy for this site. - [Acceptable Use & AI Agent Policy](https://www.mylesagnew.com/agent-policy.html): Rules for people and autonomous agents using the site and its scanner tools — no secrets, no internal targets, no bulk scanning — plus vulnerability disclosure. ## Free Security Checklists - [Cloudflare Website Security Baseline](https://www.mylesagnew.com/checklists/cloudflare-website-security-baseline.html): Step-by-step checklist for hardening a website using Cloudflare — DNS, SSL, WAF, headers, and monitoring. - [DNS Backup and Recovery](https://www.mylesagnew.com/checklists/dns-backup-recovery.html): Make DNS records versioned, recoverable, and auditable before a bad change causes downtime. (Coming soon) - [AI Agent Prompt Security](https://www.mylesagnew.com/checklists/ai-agent-prompt-security.html): Review AI-agent prompts, tool access, trust boundaries, and CI-friendly prompt checks to reduce injection risk. (Coming soon) - [Passive Cyber OSINT Triage](https://www.mylesagnew.com/osint.html): Task-first page for passive domain, URL, exposure, archive, breach-context, and evidence-preservation workflows. ## Blog Posts - [Security News (daily digest)](https://www.mylesagnew.com/blog/security-news/): Daily automatically-compiled cyber security news roundup — original headlines and short excerpts from trusted RSS feeds, each linked back to the source publisher. A curated roundup, not a republish; individual dated digests are noindex. Published most days since 2026-08-03. - [Cloudflare DNS Backup](https://www.mylesagnew.com/blog/cloudflare-dns-backup.html): Automated Bash script to back up Cloudflare DNS records via the API. (2026-06-03) - [Prepping for Boss of the SOC ANZ 2020](https://www.mylesagnew.com/blog/prepping-for-boss-of-the-soc-anz-2020.html): Getting ready for Splunk's blue-team CTF event. (2020-08-20) - [Install Ubiquiti Network Controller on Open Source Firewall Hardware](https://www.mylesagnew.com/blog/install-ubiquiti-network-controller-on-open-source-firewall.html): Step-by-step guide to running the UniFi controller on pfSense/OPNsense hardware. - [Open Source Intelligence with Open Source Firewall](https://www.mylesagnew.com/blog/open-source-intelligence-with-open-source-firewall.html): Using open source tools for OSINT alongside an open source firewall setup. ## Open Source Tools - [casaos-installation-deb13](https://github.com/mylesagnew/casaos-installation-deb13): Bash script to install CasaOS on Debian 13. - [cloudflare-backup](https://github.com/mylesagnew/cloudflare-backup): Automated Cloudflare DNS record backup script — exports all zones and records via the API. - [dns-blocklists](https://github.com/mylesagnew/dns-blocklists): Curated DNS blocklists for Pi-hole and network-level blocking. - [poc_opencti](https://github.com/mylesagnew/poc_opencti): Docker deployment for OpenCTI threat intelligence platform. - [promptgenie](https://github.com/mylesagnew/promptgenie): Prompt linting, static risk scanning, and CI tooling for AI-agent prompts. - [github-backup](https://github.com/mylesagnew/github-backup): Bash scripts to snapshot every GitHub repository owned by an account. - [n8n-json](https://github.com/mylesagnew/n8n-json): n8n automation workflows in JSON format for security alerts and pipelines. ## Security Domains - Cloud Security (AWS, Azure, GCP) — IAM, network security, encryption, compliance posture - DNS Recovery & Management — backup tooling, registrar hygiene, recovery runbooks - Web & WordPress Hardening — WAF configuration, Cloudflare hardening, attack surface reduction - DFIR Readiness — Splunk detection, Velociraptor forensics, incident response playbooks - SecDevOps Automation — Terraform, Ansible, Docker, n8n workflow pipelines - AI Agent Security — prompt injection, trust boundary review, CI-integrated prompt linting ## Contact - Website: https://www.mylesagnew.com/ - GitHub: https://github.com/mylesagnew - LinkedIn: https://www.linkedin.com/in/mylesagnew/ - Twitter/X: https://twitter.com/mylesagnew - Security reports: https://www.mylesagnew.com/.well-known/security.txt