Zion Click Create
Book a call
RESEARCH / ZION BOGGAN

The evidence ledger.

Security research, detection engineering and the tools I built to do the work. Every entry links to its code, its evidence or its disclosure.

31Disclosed findingsreported to the vendor
6Vendors and targetsFireblocks, Aiven, AXIS, Electroneum, Mattermost, one cloud platform
15High or criticalas rated on each page
19Tools and projectsbuilt and run
18Writeupsdesign and engineering notes

Counted from the pages in this ledger: disclosed findings are the Lab Notes entries marked Disclosed; vendors are distinct targets among them; high or critical uses the severity written on each page. The OpenPGP.js entry analyses a public CVE and is not counted as a finding.

02

The Evidence Ledger

The full index, every project I've designed, built, and run. Click any row for the architecture, code, and evidence.

No. / Project · 19 projects Class · Year · Status
01
★Flywheel
An autonomous vulnerability-research platform: a 7-agent decision graph that maps a target, hypothesizes bugs, drafts exploits, and only reports findings a deterministic validator could reproduce.
VULN RESEARCH
2025
ACTIVE
02
★CYCLOPS
An autonomous vulnerability-research engine: reproduced findings across 20+ open-source targets using a strict reproduce-before-report discipline. ASan crashes, live SQL rows, and executed command chains are the only valid proof.
VULN RESEARCH
2026
RESEARCH
03
Cyclops v2
A rebuild of an autonomous vulnerability research platform around one rule: only an execution artifact may declare a finding.
VULN RESEARCH
2026
RESEARCH
04
★GEMINI Malware-Research Lab
A self-contained malware-analysis lab: static-triage pipeline, ransomware detonation in a sealed VM, live memory forensics, and AES key recovery from a 4.13 GB ransomware memory dump.
VULN RESEARCH
2026
SHIPPED
05
JWT Differential Fuzzer
Feeds identical tokens into 5 JWT libraries at once and flags any disagreement. A verifier split is an auth-bypass primitive.
VULN RESEARCH
2026
RESEARCH
06
★CTI Detection Automation
Pulls live threat-intel from five feeds, deduplicates across sources, maps to ATT&CK, generates Wazuh detection rules, and holds every rule behind a human approval gate before anything reaches the SIEM.
DETECTION ENG
2025
SHIPPED
07
Detection-as-Code
Ten ATT&CK-mapped Sigma rules that compile cleanly to Splunk SPL, Elastic ES|QL, and Microsoft Sentinel KQL. Linted and tested in CI, behaviourally validated by Atomic Red Team before promotion.
DETECTION ENG
2025
SHIPPED
08
SOC Automation Lab
Wazuh detection, Shuffle SOAR, and TheHive case management wired into one pipeline. An alert fires, the indicator gets enriched, a case opens, and the analyst channel gets pinged, all before anyone clicks anything.
DETECTION ENG
2025
SHIPPED
09
Purple-Team Lab
Atomic Red Team adversary emulation against an instrumented Ubuntu endpoint: six ATT&CK techniques executed, six detections confirmed in Wazuh. The validation half of the detection-as-code pipeline.
DETECTION ENG
2025
SHIPPED
10
Secure CI/CD Pipeline
A GitHub Actions pipeline that gates every push on four parallel security checks (Semgrep SAST, gitleaks secret scan, pip-audit dependency audit, and ruff with security rules) before code is allowed to merge.
DETECTION ENG
2025
SHIPPED
11
CI/CD Supply Chain Security
Keyless Cosign signing with GitHub OIDC identity, SPDX SBOM attestation, and a Kyverno admission policy that refuses any unsigned or unattested image at the cluster boundary.
DETECTION ENG
2025
SHIPPED
12
★Perseus
A 20-agent AI orchestration platform that routes natural language commands to specialized workers across a self-hosted Proxmox homelab, with per-request cost tracking and a three-tier SSH safety model.
AI / AUTOMATION
2026
ACTIVE
13
claude-dispatch
HMAC-signed, filesystem-mediated job dispatch so two agent sessions on different hosts can hand work to each other. No broker, no open ports, no shared terminals.
AI / AUTOMATION
2026
ACTIVE
14
gpu-cpu-mutex
Two shell scripts (a GPU mutex and a CPU/RAM counting semaphore) that let multiple independent processes share one GPU and a bounded CPU budget using nothing but flock.
AI / AUTOMATION
2026
SHIPPED
15
★Pitch Tracker CV
Real-time CV aim-assist for offline MLB The Show 26: a YOLO-trained ball detector plus classical PCI tracker that predicts where each pitch will cross the plate and nudges the controller via a Titan Two adapter.
COMPUTER VISION
2025
SHIPPED
16
★DeckBound
A social idle formation auto-battler for Roblox: 33 original pixel-art champions, a server-wide world boss, shared co-op runs, and a headless build pipeline that shipped to v181.
GAME DEV
2026
LIVE
17
★Seven Star Collective
Full e-commerce and coaching platform for a fitness brand: merch store, session booking with calendar, workout challenge system, and Stripe checkout. Built in React/TypeScript on Supabase.
PRODUCT
2026
LIVE
18
Matcha Bloom
A private iOS matcha journal and Portland cafe map with quick-add logging, shareable Matcha Cards, monthly Bloom recaps, and 25 pre-seeded PDX cafe pins. Built in Flutter.
PRODUCT
2026
SHIPPED
19
WireGuard iOS Kill Switch Generator
A single Python script that wraps any WireGuard .conf file into an iOS .mobileconfig profile with IncludeAllNetworks and OnDemand auto-connect. These are the two kill-switch settings the WireGuard iOS app's UI does not expose.
PRODUCT
2026
SHIPPED
03

Lab Notes

Vulnerability research, disclosed to the vendors. Each entry gives the target, the weakness class, the severity and where it stands. Nothing is called a finding until it reproduces.

No. / Finding · Target · Class · 25 entriesSeverity · Year · Status

Fireblocks MPC-CMP library

Eight findings in Fireblocks' threshold-signature (MPC-CMP) library, disclosed to the vendor. The fix is live. Summaries below; the full write-ups, with proof, are on the code browser.

01
★Security Research Notebook
The index to every report below, by target class and method. 31 disclosed findings across 6 vendors, plus one public-CVE root-cause analysis.
INDEX
2026
PUBLISHED
02
CVE-2024-32972: GetBlockHeaders Integer Underflow Causes Full Network Denial of Service
Electroneum Smart Chain (etn-sc) · CWE-191: Integer Underflow · Critical (P1) · Disclosed
Critical (P1)
2026
DISCLOSED
03
Electroneum QBFT HasBadProposal Quorum Inconsistency Enables Permanent Consensus Stall
Electroneum Smart Chain (QBFT) · CWE-670: Always-Incorrect Control Flow Implementation · Critical (P1) · Disclosed
Critical (P1)
2026
DISCLOSED
04
Aiven Internal System Account Password Hashes Exposed via mysql.user SELECT
Aiven for MySQL · CWE-522: Insufficiently Protected Credentials · High (P2) · Disclosed
High (P2)
2026
DISCLOSED
05
Authenticated DoS: Dragonfly Server Crash via Crafted Stream RESTORE Payload
Aiven for Dragonfly · CWE-770: Allocation of Resources Without Limits · High (P2) · Disclosed
High (P2)
2026
DISCLOSED
06
Autovacuum Arbitrary Code Execution via Expression Index Shadow Functions
Aiven for PostgreSQL · CWE-269: Improper Privilege Management · High (P2) · Disclosed
High (P2)
2026
DISCLOSED
07
Persistent DoS via GZIP Compression Bomb in Aiven Karapace REST Proxy
Aiven for Kafka (Karapace) · CWE-400: Uncontrolled Resource Consumption · High (CVSS 7.5) · Disclosed
High (CVSS 7.5)
2026
DISCLOSED
08
Silent Data Corruption and Persistent Backdoor via Unrestricted redis.set_repl in Aiven Valkey
Aiven for Valkey · CWE-284: Improper Access Control · High (P2) · Disclosed
High (P2)
2026
DISCLOSED
09
Stack Overflow in JSONMergePatch Crashes Aiven Managed ClickHouse via Single SELECT Query
Aiven for ClickHouse · CWE-674: Uncontrolled Recursion · High (P1) · Disclosed
High (P1)
2026
DISCLOSED
10
aiven_gatekeeper Bypass via Implicitly Castable Argument Types
Aiven for PostgreSQL · CWE-285: Improper Authorization · High (P2) · Disclosed
High (P2)
2026
DISCLOSED
11
AXIS OS ONVIF RTSP-over-WebSocket Endpoint Missing Authentication
AXIS OS (P3245-LV firmware) · CWE-862: Missing Authorization · High · Disclosed
High
2026
DISCLOSED
12
AXIS OS httptest.cgi SSRF via IPv6-Mapped Loopback Bypass
AXIS OS (P3245-LV firmware) · CWE-918: Server-Side Request Forgery · High (CVSS 7.6) · Disclosed
High (CVSS 7.6)
2026
DISCLOSED
13
Two SSRF Vulnerabilities in a Cloud Image Pipeline
Cloud media-processing platform (undisclosed per program policy) · CWE-918: Server-Side Request Forgery · High / Medium · Disclosed
High / Medium
2026
DISCLOSED
14
Mattermost Shared Channel Invite API Missing Channel-Level Authorization
Mattermost Server · CWE-862: Missing Authorization · High (CVSS 7.7) · Disclosed
High (CVSS 7.7)
2026
DISCLOSED
15
Root-Cause Analysis: OpenPGP.js CVE-2025-47934
OpenPGP.js · CWE-345: Insufficient Verification of Data Authenticity · High (public CVE) · Public Cve
High (public CVE)
2026
PUBLIC CVE
16
ASLR Bypass via Lua Function Pointer Leak in Aiven Managed Valkey
Aiven for Valkey · CWE-200: Exposure of Sensitive Information · Medium (P3) · Disclosed
Medium (P3)
2026
DISCLOSED
17
Customer-Triggerable Superuser dblink Session via SECURITY DEFINER Chain
Aiven for PostgreSQL · CWE-269: Improper Privilege Management · Medium (P3) · Disclosed
Medium (P3)
2026
DISCLOSED
18
Privilege Boundary Violation via Subscription Ownership Escalation
Aiven for PostgreSQL · CWE-269: Improper Privilege Management · Medium (P3) · Disclosed
Medium (P3)
2026
DISCLOSED
19
Unauthenticated Query Storage and Cross-User IDOR in Aiven SQL Optimizer
Aiven API · CWE-639: Authorization Bypass Through User-Controlled Key · Medium (P3) · Disclosed
Medium (P3)
2026
DISCLOSED
20
AXIS OS SNMP Community String Disclosure to Viewer-Privileged Users
AXIS OS (P3245-LV firmware) · CWE-200: Exposure of Sensitive Information to Unauthorized Actor · Medium (CVSS 6.5) · Disclosed
Medium (CVSS 6.5)
2026
DISCLOSED
21
AXIS OS dnsupdate.cgi Delete Path Missing Input Validation
AXIS OS (P3245-LV firmware) · CWE-20: Improper Input Validation · Medium (CVSS 4.7) · Disclosed
Medium (CVSS 4.7)
2026
DISCLOSED
22
AXIS OS pingtest.cgi SSRF via Missing validateaddr Call
AXIS OS (P3245-LV firmware) · CWE-918: Server-Side Request Forgery · Medium (CVSS 5.0) · Disclosed
Medium (CVSS 5.0)
2026
DISCLOSED
23
User Email Enumeration via Error Message and Timing Difference at Aiven Login
Aiven API · CWE-204: Observable Response Discrepancy · Low to Medium · Disclosed
Low to Medium
2026
DISCLOSED
24
Aiven Customer List Enumeration via 403/404 Response Differentiation on Project Endpoint
Aiven API · CWE-204: Observable Response Discrepancy · Low · Disclosed
Low
2026
DISCLOSED
25
Incomplete CVE-2025-31480 Remediation: Unqualified parse_ident in SECURITY DEFINER Function
Aiven for PostgreSQL · CWE-426: Untrusted Search Path · Low (P4) · Disclosed
Low (P4)
2026
DISCLOSED
04

Writing

Notes on the projects I build: the decisions, the tradeoffs, and what the work taught me.

01
Claude Code for People Who Think It Is a Chat Window
A first-day guide for anyone who has only used Claude in a browser. Real session screenshots, the permission model explained as a key ring, and how to run an agent autonomously without handing it the keys to everything.
WRITING
2026
2026-08-18
02
The packet is the boundary
What a public IEC 61850 advisory teaches about protocol boundaries, parser assumptions, and the facts that still need local verification.
WRITING
2026
2026-08-10
03
A Control Is Not a Policy
Control design that survives an audit rather than a document that describes one, and the tests that tell the difference.
WRITING
2026
2026-08-07
04
Evidence is not theatre
A practical evidence chain for proving scope, source, result, receipt, and review.
WRITING
2026
2026-08-05
05
The policy is current. The behavior is not.
A quarterly reality check for the gap between written policy and the system doing the work.
WRITING
2026
2026-08-02
06
Green is not done
Why agent work needs an authority check and a receipt instead of a status color alone.
WRITING
2026
2026-07-29
07
Make the bad outcome unrepresentable
Designing pipelines so silent drops and guessed remaps are not valid outcomes.
WRITING
2026
2026-07-25
08
How I Run a Crew of AI Agents
Sixteen projects in four days, run by a crew of routed AI agents while I was away from my desk. The same operating model told at four depths, from a plain-language version anyone can read to the full methods paper with figures.
WRITING
2026
2026-07-11
09
Watchdog for the labs. Audit log for your agents.
The oversight wave aimed at frontier labs has already cascaded one level down, to everyone who deploys AI coding agents. Here is the demand underneath the headlines, why most tooling answers it with another black box, and the record I think actually holds up.
WRITING
2026
2026-06-19
10
Git records what changed. It does not record how you got there
When an AI coding session ends, the steering disappears: the misunderstandings, the corrections, the abandoned branch. TreeTrace reconstructs that from the local transcript and refuses to let a model judge it.
WRITING
2026
2026-06-12
11
Two implementations that have to agree to the byte
Maintaining a cryptographic provenance protocol with a Rust canonical core and a Python reference, where bit-identical conformance is not a nice-to-have. It is the spec.
WRITING
2026
2026-05-16
12
When two libraries disagree about a token
A JWT library that accepts a token another library rejects, on byte-identical input, is an auth-bypass primitive. This is the harness that hunts for that disagreement live.
WRITING
2026
2026-03-30
13
One interface for a homelab that grew teeth
Most homelab automation is a pile of shell scripts you have to remember. Perseus is the version where I send one message and the right agent handles it, with the cost on the receipt.
WRITING
2026
2026-02-11
14
Fitting a parabola to a video game pitch
A computer-vision accessibility tool that watches a capture-card feed, predicts where the pitch crosses the plate, and nudges the controller. Built for offline play only, on purpose.
WRITING
2025
2025-09-27
15
Proving the artifact, not just the source
A clean source scan and a build step are not a chain of custody. Here is the supply-chain layer that closes the gap, with no private key to lose.
WRITING
2025
2025-07-14
16
Four gates before merge, and why they run apart
A CI pipeline that fans security checks out into separate jobs, so a red build tells you which gate tripped instead of handing you one long log to scroll.
WRITING
2025
2025-06-09
17
The three things I did by hand on every alert
Building a SOC lab where everything between the rule match and the analyst is automated, because the manual version does not scale and I was tired of it.
WRITING
2025
2025-04-22
18
Writing detections once and meaning it
Why I moved my detection rules out of the SIEM and into source control, and what it cost me to do it.
WRITING
2025
2025-03-18