I want to be the reason your pager stays silent.
Building security tools for the moments when evidence matters.
I build the kind of tools I would want during an incident: local-first where sensitive data is involved, explicit about uncertainty, and easy to inspect. My work spans Windows PE analysis, macOS host inspection, and Linux security research.
|
Focused utilities for endpoint triage, threat hunting, compromise assessment, and defensive automation. |
Reproducible evidence, clear limitations, reviewable code, and verifiable release artifacts. |
Single-file Windows malware triage for PE static analysis, case investigation, and opt-in IOC enrichment.
|
Read-only macOS compromise assessment across 24 inspection modules with terminal, HTML, and JSON reports. |
Experimental Linux security research around SSH hardening, brute-force detection, and SIEM forwarding. |
|
Corrected resource parsing for low-alignment PE images and added regression coverage. Reviewed and merged upstream. Follow-up: test-suite consolidation in issue #584. |
Updated September 2026.
[active] HORUS hostile-input testing
[next] machunt output redaction
[review] ssh-fortress safety hardening
[upstream] pefile #584 test consolidation
Bug reports and reproducible edge cases are welcome. If you use one of my tools, tell me what worked, what failed, and what evidence helped.