Projects & research
9 totalManifestTrace
Android manifest exposure scanner, generalising my own CVE-2025-50861 and CVE-2025-50862 into five checks against a from-scratch AXML parser. On PyPI.
pipx install manifest-trace RuntimeTrace
eBPF-powered runtime consistency checker for Linux: does the kernel's own view of what's running agree with ps, lsmod and friends? On PyPI.
sudo runtime-trace --watch 30 Hayabusa Lens
A dashboard for Hayabusa and Chainsaw: a 3D attack map and an AI investigator that keeps an audit trail of every question it asks. Local-first, MIT, on PyPI.
pipx install hayabusa-lens PhantomTrace
Read-only NTFS consistency checker for DFIR. Compares the MFT, cluster bitmap and run lists and flags where they disagree, a possible sign of tampering. On PyPI.
pipx install phantom-trace-ntfs CVE advisories
Public write-ups for the vulnerabilities I've found and responsibly disclosed, including CVE-2025-50861 and CVE-2025-50862 in the Lotus Cars Android app.
Operation Homelab
A Proxmox lab on a Dell R620 with five 3D battle maps: network, cyber range, 20-container malware zoo, SOC/DFIR + AI, and a mobile/macOS bench. Includes a range builder and a build-your-own guide.
SOC & DFIR with Velociraptor
A blue-team pipeline in my homelab: endpoint hunting and triage with Velociraptor, logs in a SIEM, and a separate evidence store for case work.
Sigma detection rules
Detection engineering as code: Sigma rules written, tested against attack simulations, and shipped to the SIEM through Git.
AI agent swarms for security
LangChain agents that triage alerts, pull related logs and summarise investigations, with every prompt and tool call logged.