cat about.md

bash

$ whoami

software developer · security researcher · trained journalist

I work at the intersection of full-stack development, cybersecurity research, and journalism. By day I ship web applications; by night I'm usually elbow-deep in breach data, ransomware group genealogies, or a packet capture that raised more questions than it answered. This site is where the security half of that work gets written down.

the security work

My research covers the global threat landscape, with particular attention to regions that get breached constantly and written about rarely. A lot of significant incidents worldwide go undocumented, unattributed, or misreported — the public record is thinner than most people assume, and I'm trying to close some of that gap.

Ongoing areas of work include:

the journalism work

I'm a Journalism graduate, specialized in Broadcast Production — and it shows in how this site operates. Security research and journalism turn out to be the same discipline wearing different clothes: source verification, evidence chains, attribution standards, and the obligation to publish what you can prove rather than what makes the better headline. The editorial training is why every writeup here treats sourcing as non-negotiable, and why "a guy on a forum said so" never qualifies as confirmation.

the developer work

The engineering background is what keeps the research honest — I don't just read about systems, I build and break them. Working stack:

Past builds range from civic-tech platforms to record-keeping systems for low-connectivity environments — software for contexts where infrastructure is inconsistent and the design has to assume nothing.

principles

A few rules this site runs on:

  1. Evidence over vibes. Every claim traces back to something verifiable — a leak site, a disclosure, a capture, a reproducible test.
  2. Attribution with humility. Threat-actor attribution is stated with confidence levels, not certainty theater.
  3. Defang everything. No live links to hostile infrastructure. Ever.
  4. Authorized targets only. Techniques documented here are for authorized engagements, CTFs, defensive research, and education. Nothing here is an invitation, an instruction manual for crime, or legal advice.
  5. Write it down. Undocumented research might as well not have happened.

why this exists

The global threat landscape deserves primary-source documentation, not just summaries filtered through vendors selling something. This log is one small contribution to that record — kept mostly for my own reference, shared in case it saves someone else a late night.

bash

$ echo "still curious"

still curious

contact

Reach out via the links in the footer, or open an issue on the repo behind this site.

If a writeup here saved you a late night, buying me a coffee is the going rate — no ads, no sponsor posts, no funding calculus creeping into the sourcing.