Tools built around real operator problems.
Private products, focused public tools, and deliberately vulnerable labs. Each project starts with a workflow that existing products make harder than it needs to be.
Four products. One operator loop.
The portfolio is not a pile of unrelated tools. Each product answers a different question—from what is exposed to what the defense can actually detect.
XRAY ASM
A private, evidence-driven attack surface management workbench for discovering, relating, and prioritizing external exposure without confusing candidates with verified findings.
- Normalize domains, hosts, services, APIs, screenshots, and mobile surface
- Connect assets with provenance-aware, explainable relationships
- Separate discovery candidates, observations, exposures, and verified findings
- Prioritize operator review without silently authorizing target contact
GothamCity
A private adversary-emulation and detection-validation platform that turns ATT&CK techniques, Atomic Red Team tests, LOLBAS tradecraft, and controlled agents into measurable defensive coverage.
- Compose repeatable campaigns from ATT&CK techniques and threat-actor profiles
- Enrich operator plans with Atomic Red Team and LOLBAS execution context
- Separate staged, simulated, and live-agent execution states
- Turn campaign results into tactic-level detection coverage and blind spots
agentmordor
Evidence-backed authority mapping for AI agents — see which identity, tool, data, and external action are connected before deployment.
- Map input, agent, tool, identity, and reachable action
- Compare newly introduced authority in a pull request
- Run the core analysis without requiring a model API
- Keep secret values redacted and configuration analysis read-only
Methodology
A private operator knowledge system spanning 22 security domains, with one shared contract for authorization, evidence quality, false-positive review, proof of impact, and reporting.
- Route an assessment through 22 specialist security domains
- Apply one authorization and execution-tier contract everywhere
- Turn signals into findings through evidence and false-positive gates
- Keep engagement data outside the reusable knowledge library
- 01 Scope
- 02 Hypothesis
- 03 Tier
- 04 Evidence
- 05 Review
- 06 Report
Open-source projects
Smaller public tools and training applications with an explicit purpose and reproducible workflow.
ghostlink
Covert C2 channel over legitimate platforms — stealthy command and control for authorized red team operations.
evilcorp-ios
Intentionally vulnerable iOS application for mobile security training, with challenges across OWASP MASVS categories.
driftnet2
Network traffic interception and analysis toolkit for passive reconnaissance and protocol inspection.
Interactive Security Simulators
Deterministic, zero-dependency policy evaluators running directly in your browser. Test authorization boundaries, resolve Kerberos delegation paths, and verify Apple platform requirements in real time.
macOS Entitlement Evaluator
Interactive security analyzer for macOS XPC peer validation, SecRequirement strings, PID reuse races, and Hardened Runtime boundaries.
AD Delegation Risk Resolver
Simulate Unconstrained, Constrained, S4U2Self, and RBCD attack paths with real-time Protected Users and MachineAccountQuota defense verification.
AI Pentest Execution Broker
Policy enforcement engine gating autonomous agent actions: scope bounds, reversible canary checks, and multi-tier approval states.
