offensive security · capability development
Capability development for operators who can't afford to guess.
Breaking things professionally since 2012. Building the platforms that make authorized offensive work repeatable, sovereign, and quiet.
Commercial tooling assumes clean networks, permissive egress, and telemetry someone else owns. We build for the environment operators actually get.
Scope, rules of engagement, and teardown are not paperwork. They are part of the system.
Target data, forensic material, and model outputs belong in the operator environment. Not a vendor cloud.
operating principles
~/selected-work
LuciMAGI
in developmentFully local security-research assistant — staged assessment pipeline, Ornith heavy reasoning, Kali tool container, 42-skill corpus, and auditable operator cases.
Position-Independent Agent
activeCross-platform remote agent compiled to zero-dependency, position-independent shellcode — no libc, no CRT, TLS 1.3 and WebSocket from scratch.
CVE-2023-33105
publishedPublished Qualcomm WLAN research: transient denial-of-service in WLAN host/firmware triggered by malformed authentication-frame behavior.
Poseidon-X
activeSovereign campaign simulation infrastructure for authorized red teams — multi-host deployment, operator-owned mail, integrated email auth assessment (Wraith), audit trails, and no vendor telemetry.
Mammon
activeLocal forensic evidence analysis - multilingual audio, vision, entity correlation, identity clusters, and hybrid search.
RADAR-X
pre-releaseDistributed network intelligence at national scale - regional worker pairs, VPN-isolated egress, MQTT orchestration, and Postgres-backed results.