The evidence ledger.
Security research, detection engineering and the tools I built to do the work. Every entry links to its code, its evidence or its disclosure.
Security research, detection engineering and the tools I built to do the work. Every entry links to its code, its evidence or its disclosure.
Counted from the pages in this ledger: disclosed findings are the Lab Notes entries marked Disclosed; vendors are distinct targets among them; high or critical uses the severity written on each page. The OpenPGP.js entry analyses a public CVE and is not counted as a finding.
My strongest projects, explained plainly first, then the technical detail.
A visibility layer for AI coding-agent sessions: a structured, local, redacted record of what an agent did, what it was refused or denied, where a human stepped in, and what touched secrets or auth.
Coding agents touch authentication, secrets, access control, and production on their own, and the steering that shaped a session disappears when it ends. Git records what changed, not how the agent got there. EU AI Act, SOC 2, and ISO 42001 now expect a verifiable record, and most tooling answers with another black box graded by a model.
I built the record GRC and audit teams ask for. TreeTrace turns a raw session into a local, vendor-neutral evidence trail: prompt lineage, tools and files touched, secrets and auth contact, refusals and permission denials, and the human corrections that pulled the agent back. Every flag is a deterministic heuristic with evidence you can open and re-derive. No LLM judge anywhere, and redaction fails closed.
A deterministic, evidence-backed audit record that supports EU AI Act, SOC 2, and ISO 42001 reviews and runs entirely on the machine. Source-available and noncommercial.
An autonomous, multi-agent platform that researches software for security vulnerabilities and verifies them before reporting.
Vulnerability research is slow, manual work, and AI tools tend to invent “findings” that don't actually reproduce, wasting triage time and eroding trust.
I designed and built the whole system: a staged decision graph that maps a target, forms a hypothesis, drafts a proof-of-concept, and only reports a finding once a deterministic validator reproduces it end-to-end.
Reproduced proof-backed findings across 20+ open-source projects under a strict reproduce-before-report standard. Built strictly for authorized testing.
A sealed, air-gapped lab for safely analyzing real malware and practicing forensic investigation.
Responding to ransomware means recovering evidence from an infected machine without letting the malware spread or losing what happened.
I stood up the isolated environment, detonated real ransomware, captured a 4.1 GB live memory image, and wrote a scanner that recovered the encryption keys from memory, then rebuilt the attack timeline.
Recovered AES key schedules from memory and reconstructed the full encryption timeline. Every claim is backed by captured evidence.
A single source of truth for security detections that compiles to multiple SIEM platforms automatically.
Detection rules drift, go untested, and get rewritten by hand for every SIEM, so gaps and false positives pile up.
I wrote Sigma detections mapped to MITRE ATT&CK, added automated linting and tests in CI, and compiled them from one source to Splunk, Microsoft Sentinel, and Elastic.
Validated, version-controlled detections that stay consistent across three SIEM platforms with audit-ready test evidence.
An open-source system for cryptographically proving where data came from and that it hasn't been tampered with.
As AI-generated and forged content grows, organizations need a tamper-evident way to verify the origin and integrity of files.
I'm the lead maintainer. I built a Rust core and a matching Python reference implementation with bit-identical results, using modern and post-quantum cryptography plus a public transparency log.
12-crate Rust workspace with a conforming Python implementation and 141 tests. Live and public.
The full index, every project I've designed, built, and run. Click any row for the architecture, code, and evidence.
Vulnerability research, disclosed to the vendors. Each entry gives the target, the weakness class, the severity and where it stands. Nothing is called a finding until it reproduces.
Eight findings in Fireblocks' threshold-signature (MPC-CMP) library, disclosed to the vendor. The fix is live. Summaries below; the full write-ups, with proof, are on the code browser.
Notes on the projects I build: the decisions, the tradeoffs, and what the work taught me.