/projects
Work
Working systems across red team infrastructure, mobile assessment, network intelligence, forensic analysis, and embedded visibility.
LuciMAGI
Fully local security-research assistant — staged assessment pipeline, Ornith heavy reasoning, Kali tool container, 42-skill corpus, and auditable operator cases.
Position-Independent Agent
Cross-platform remote agent compiled to zero-dependency, position-independent shellcode — no libc, no CRT, TLS 1.3 and WebSocket from scratch.
CVE-2023-33105
Published Qualcomm WLAN research: transient denial-of-service in WLAN host/firmware triggered by malformed authentication-frame behavior.
RADAR-X
Distributed network intelligence at national scale - regional worker pairs, VPN-isolated egress, MQTT orchestration, and Postgres-backed results.
OPSINT
Mobile red-team operations for authorized Android assessments - stock-device collection, encrypted operator channels, dashboard, and evidence export.
Mammon
Local forensic evidence analysis - multilingual audio, vision, entity correlation, identity clusters, and hybrid search.
Poseidon-X
Sovereign campaign simulation infrastructure for authorized red teams — multi-host deployment, operator-owned mail, integrated email auth assessment (Wraith), audit trails, and no vendor telemetry.
ARCHON
Android forensics built like a product - selective extraction, native Rust UI, relationship graphs, reports, and SHA-256 integrity.
rcap-ng
Visibility from inside the router - remote libpcap for embedded Linux, Zeek alerts, Prometheus metrics, and replayable captures.
FuckWinDefend
Windows Defender and SmartScreen teardown for authorized lab work — registry hardening, safe-mode reboot path, service control, backups, and reboot persistence.
origin-recon
CDN origin discovery for authorized assessments - passive pivots, live validation, confidence-graded candidates, and diffable reports.
Argus
Passive RF counter-surveillance on hardware you own - edge motes, metadata-only sightings, identity despite MAC randomization, and operator alerts.