cat about.md
$ whoami
software developer · security researcher · trained journalist
I work at the intersection of full-stack development, cybersecurity research, and journalism. By day I ship web applications; by night I'm usually elbow-deep in breach data, ransomware group genealogies, or a packet capture that raised more questions than it answered. This site is where the security half of that work gets written down.
the security work
My research covers the global threat landscape, with particular attention to regions that get breached constantly and written about rarely. A lot of significant incidents worldwide go undocumented, unattributed, or misreported — the public record is thinner than most people assume, and I'm trying to close some of that gap.
Ongoing areas of work include:
- Breach documentation and attribution — structured cataloguing of dark web disclosures and confirmed incidents, with threat-actor attribution grounded in evidence. If a claim can't be traced to a leak site posting, a disclosure, or corroborating data, it doesn't make the record.
- Threat-actor evolution tracking — following ransomware groups through law-enforcement disruptions, rebrands, and reformations. Groups don't die; they refactor. All reference links defanged.
- Breach aftermath analysis — deep-dives into what happensafter the headline fades: the long tail of mass-exploitation campaigns, secondary redistribution of stolen data, and "dark data" scenarios where leaked records resurface years later in new contexts.
- Myth-busting bad statistics — disputed cyber-attack figures get repeated until they harden into "fact." I dismantle widely-cited numbers by grounding the argument in verifiable incidents instead of recycled vendor claims.
- OSINT and information-environment monitoring — open-source intelligence work spanning multilingual NLP, sentiment analysis, and disinformation detection, built on locally-hosted LLM tooling and compliant data sources.
the journalism work
I'm a Journalism graduate, specialized in Broadcast Production — and it shows in how this site operates. Security research and journalism turn out to be the same discipline wearing different clothes: source verification, evidence chains, attribution standards, and the obligation to publish what you can prove rather than what makes the better headline. The editorial training is why every writeup here treats sourcing as non-negotiable, and why "a guy on a forum said so" never qualifies as confirmation.
the developer work
The engineering background is what keeps the research honest — I don't just read about systems, I build and break them. Working stack:
- Frontend: React, Next.js, TypeScript
- Backend: Node/Express (MERN), Ruby on Rails
- Elsewhere: local LLM tooling (Ollama/vLLM), scrapers, automation bots, and whatever glue code a given investigation demands
Past builds range from civic-tech platforms to record-keeping systems for low-connectivity environments — software for contexts where infrastructure is inconsistent and the design has to assume nothing.
principles
A few rules this site runs on:
- Evidence over vibes. Every claim traces back to something verifiable — a leak site, a disclosure, a capture, a reproducible test.
- Attribution with humility. Threat-actor attribution is stated with confidence levels, not certainty theater.
- Defang everything. No live links to hostile infrastructure. Ever.
- Authorized targets only. Techniques documented here are for authorized engagements, CTFs, defensive research, and education. Nothing here is an invitation, an instruction manual for crime, or legal advice.
- Write it down. Undocumented research might as well not have happened.
why this exists
The global threat landscape deserves primary-source documentation, not just summaries filtered through vendors selling something. This log is one small contribution to that record — kept mostly for my own reference, shared in case it saves someone else a late night.
$ echo "still curious"
still curious
contact
Reach out via the links in the footer, or open an issue on the repo behind this site.
If a writeup here saved you a late night, buying me a coffee is the going rate — no ads, no sponsor posts, no funding calculus creeping into the sourcing.