Projects & research

9 total
released · featured

ManifestTrace

Android manifest exposure scanner, generalising my own CVE-2025-50861 and CVE-2025-50862 into five checks against a from-scratch AXML parser. On PyPI.

pipx install manifest-trace
DFIRAndroidmobile-securitypythonCVE write-up GitHub ↗ PyPI ↗
released · featured

RuntimeTrace

eBPF-powered runtime consistency checker for Linux: does the kernel's own view of what's running agree with ps, lsmod and friends? On PyPI.

sudo runtime-trace --watch 30
DFIReBPFLinuxpythonrootkit-detection write-up GitHub ↗ PyPI ↗
released · featured

Hayabusa Lens

A dashboard for Hayabusa and Chainsaw: a 3D attack map and an AI investigator that keeps an audit trail of every question it asks. Local-first, MIT, on PyPI.

pipx install hayabusa-lens
DFIRSigmaAIpythonEVTX write-up GitHub ↗ PyPI ↗
released · featured

PhantomTrace

Read-only NTFS consistency checker for DFIR. Compares the MFT, cluster bitmap and run lists and flags where they disagree, a possible sign of tampering. On PyPI.

pipx install phantom-trace-ntfs
DFIRNTFSanti-forensicspython write-up GitHub ↗ PyPI ↗
released · featured

CVE advisories

Public write-ups for the vulnerabilities I've found and responsibly disclosed, including CVE-2025-50861 and CVE-2025-50862 in the Lotus Cars Android app.

AndroidCVEmobile security GitHub ↗
active · featured

Operation Homelab

A Proxmox lab on a Dell R620 with five 3D battle maps: network, cyber range, 20-container malware zoo, SOC/DFIR + AI, and a mobile/macOS bench. Includes a range builder and a build-your-own guide.

homelabProxmoxcyber range write-up
active · featured

SOC & DFIR with Velociraptor

A blue-team pipeline in my homelab: endpoint hunting and triage with Velociraptor, logs in a SIEM, and a separate evidence store for case work.

SOCDFIRVelociraptor write-up
active

Sigma detection rules

Detection engineering as code: Sigma rules written, tested against attack simulations, and shipped to the SIEM through Git.

Sigmadetection engineeringSOC write-up
research

AI agent swarms for security

LangChain agents that triage alerts, pull related logs and summarise investigations, with every prompt and tool call logged.

AI agentsLangChainSOC write-up