Skip to content
View mobinert's full-sized avatar

Block or report mobinert

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mobinert/README.md

Mobin Erteghaie — Security Engineering, Threat Hunting, Open Source

Windows PE triage, macOS compromise assessment, Linux hardening research

I want to be the reason your pager stays silent.
Building security tools for the moments when evidence matters.



LinkedIn ORCID Open-source projects


About

I build the kind of tools I would want during an incident: local-first where sensitive data is involved, explicit about uncertainty, and easy to inspect. My work spans Windows PE analysis, macOS host inspection, and Linux security research.

🎯 What I build

Focused utilities for endpoint triage, threat hunting, compromise assessment, and defensive automation.

🧭 How I work

Reproducible evidence, clear limitations, reviewable code, and verifiable release artifacts.


Featured work

HORUS — Windows PE triage and IOC enrichment

Single-file Windows malware triage for PE static analysis, case investigation, and opt-in IOC enrichment.

HORUS latest release HORUS build status C++ for Windows MIT license

Source · Documentation · Latest release

Read-only macOS compromise assessment across 24 inspection modules with terminal, HTML, and JSON reports.

machunt latest release Bash for macOS

Source · Docs · Release

Experimental Linux security research around SSH hardening, brute-force detection, and SIEM forwarding.

Experimental status Python for Linux

Source · Docs · Research release

HORUS and machunt are released tools. ssh-fortress remains experimental and is not recommended for production deployment.

Open-source contribution

Merged into pefile

Corrected resource parsing for low-alignment PE images and added regression coverage. Reviewed and merged upstream.

Follow-up: test-suite consolidation in issue #584.


Working stack

C++ Bash Python CMake PowerShell GitHub Actions
Windows macOS Linux DFIR Threat hunting

Current focus

Updated September 2026.

[active]   HORUS        hostile-input testing
[next]     machunt      output redaction
[review]   ssh-fortress safety hardening
[upstream] pefile #584  test consolidation

Contact

Bug reports and reproducible edge cases are welcome. If you use one of my tools, tell me what worked, what failed, and what evidence helped.

Inspect the evidence. Reduce the uncertainty.

@mobinert's activity is private