The central Brain and coordination plane of a distributed security ecosystem. ARACHNE orchestrates collection and analysis, preserves execution and evidence provenance, and turns independent security capabilities into one research environment.
BRAIN↔
ARACHNE is deliberately not a monolith. Major capabilities run as independently deployable platforms with their own Docker and runtime boundaries, exposing normalized data back to the central Brain.
Standard APIs allow one platform's output to become another's input. Findings, artifacts, IOCs, runtime telemetry and provenance converge through Hermes and Composite Assets before returning to the wider ARACHNE operating context.
root@arachne:~$ correlate --stream all --preserve-provenancesha256:4a6f81d2c90e...7b13 / fabric_rev:24.8
[ACQ.01] ONLINE
SHOGUN
INFRASTRUCTURE INTELLIGENCE
RDAP/DNS/CT7F3A:19C2
[ACQ.02] RX
ODIN EYE
EXTERNAL-SOURCE INGESTION
RSS/TG/EXT09DE:A817
[ACQ.03] TRACE
SESSIONS
RUNTIME EVIDENCE
HAR/DOM/NET3C81:4F0B
[ACQ.04] RX
CHARON
ON-CHAIN MALWARE MONITOR
EVM/RPC/JSE7A2:6C4D
[ANL.01] EXEC
JS NINJA
JAVASCRIPT REVERSE ENGINEERING
AST/CFG/IOCBB21:EF40
[ANL.02] EXEC
MOIRAI
EXTENSION ANALYSIS
CRX/HAR/DYND5A4:71E9
[ANL.03] LAB
ONYX VEIL
MOBILE APP ANALYSIS
APK/DEX/IOC11AC:88F3
[ANL.04] ONLINE
JOROGUMO
ARTIFACT / YARA INSPECTION
YARA/ROUTEA290:31DD
[INV.01] LINK
WEAVER
CASE / INVESTIGATION LAYER
CASE/TASK/LEDGER4E07:C618
[INV.02] DESIGN
SILK
ANALYST WRITEUP SYSTEM
NOTE/LINK/EXPORT0F93:EA77
[INT.01] ONLINE
HERMES
THREAT INTELLIGENCE / ENRICHMENT
IOC/STATE/PIVOTC441:08AE
[DAT.01] SYNC
COMPOSITE ASSETS
CANONICAL ENTITY / EVIDENCE GRAPH
ENTITY/EDGE/PROV9B60:2D14
+
+
0x7F ▓░ TRACE::MISMATCH
/SPECIALIZED PLATFORMS
INDEPENDENT RUNTIMES → UNIFIED EVIDENCE
/01 ACTIVE
Domain & infrastructure intelligence
SHOGUN
Maintains infrastructure profiles, timelines, correlations and rescans across WHOIS/RDAP, DNS, certificates, ASN, CSP and passive subdomain intelligence.
MASTERDOMAINSRDAPDNSCERTIFICATES
/02 ACTIVE
Threat-intelligence & enrichment plane
HERMES
Maintains observables, observations, state transitions and provider integrations, with direct bridges into the Brain, Shogun and JS Ninja.
THREATFOXMALTRAILOTXVIRUSTOTAL
/03 ACTIVE
JavaScript analysis workbench
JS NINJA
Tracks immutable artifact versions, findings, symbols, transformations, provenance, relationships, IOC sightings and analyst annotations.
ARTIFACTSPROVENANCETRANSFORMSFINDINGS
/04 ACTIVE
Browser-extension analysis
MOIRAI
Unpacks CRX/ZIP packages, analyzes manifests, permissions, IOCs and scripts, and executes extensions through instrumented browser workers.
CRXMANIFESTHARDYNAMIC EXECUTION
/05 ACTIVE
External-source ingestion plane
ODIN EYE
Normalizes external-source intelligence into one extensible model. RSS/Talkwalker and Telegram are the current collection lanes.
INGESTIONNORMALIZATIONRSSTELEGRAM
/06 ACTIVE
Deployment & interaction inspection
JANUS
Creates stable project URLs, configurable pages and endpoints, snapshot history, and request/observable inspection against deployed projects.
ENDPOINTSSNAPSHOTSINSPECTOROBSERVABLES
/07 ACTIVE
Artifact & YARA inspection
JOROGUMO
Routes artifact scans under Brain-managed policy, synchronizes rules, records scan history and applies pressure guardrails to dispatch.
YARAROUTINGRULE SYNCGUARDRAILS
/08 EARLY STAGE
Mobile application analysis
ONYX VEIL
Accepts APKs, runs manifest, permission and string analysis in isolated workers, and returns normalized findings through the Brain bridge.
APKISOLATED WORKERSMANIFESTFINDINGS
/09 ACTIVE
Federated execution plane
SYNAPSE
Places, leases and observes security workloads across controlled worker pools, execution classes, zones and trust boundaries.
ORCHESTRATIONLEASESWORKER POOLSFEDERATION
/10 PROTOTYPE
Evidence, assurance & audit intelligence
STRATUM
A planned layered evidence and analysis platform. Real ingestion, ClickHouse analysis and Muninn integration remain in prototype/integration phase.
EVIDENCECLICKHOUSEASSURANCEMUNINN
/11 EVOLVING
Shared security substrate
NEMEAN
Provides safe browser/UI primitives, CSP and security-header generation, and shared boundary and content-inspection contracts.
CITADELBASTIONWARDSENTINEL
/12 DESIGN
Investigation writeup system
SILK
An Obsidian-like analyst editor designed to live-link findings, IOCs, artifacts, code, browser evidence and flow results into narratives.
WRITEUPSLIVE LINKSNARRATIVESEVIDENCE
/13 ACTIVE
Egress & VPN orchestration layer
SPINNERET
Routes worker traffic through switchable NordVPN exit nodes with country/city selection, per-target-group egress, a fail-closed kill switch and live GeoIP globe.
NORDVPNEGRESSKILL SWITCHGEOIP
/14 ACTIVE
Case & investigation layer
WEAVER
Organizes case items, notes, links, timelines, tasks, observable ledgers and attached evidence into unified ARACHNE investigations.
CASESTIMELINESOBSERVABLESEVIDENCE
/15 ACTIVE
Entity & evidence graph
COMPOSITE ASSETS
Correlates canonical entities, relationships, findings, artifacts and provenance into a shared graph for enrichment and investigation pivots.
ENTITIESRELATIONSHIPSPROVENANCECORRELATION
/16 ACTIVE
On-chain malware & EtherHiding monitor
CHARON
Scans live and historical blockchain activity for smart-contract payloads, validates and classifies extracted JavaScript, and routes detections into JS Ninja, Spinneret and ARACHNE workflows.
ETHERHIDINGEVM CHAINSJS PAYLOADSDETECTIONS
/PROFILEANALYST + RESEARCHER
OPERATING PRINCIPLE
OBSERVATION BEFORE ASSUMPTION.
I work where malicious code, applications, infrastructure, and evidence meet. The objective is not simply to label an artifact or identify a weakness, but to reconstruct adversary behavior, validate impact, and produce defensible security conclusions.
My work spans offensive and defensive security, combining reverse engineering, penetration testing, adversarial simulation, and intelligence-led investigation with evidence-based auditing across enterprise and cloud environments.
A01/04
Malware analysis & reverse engineering
Threat analysis, layered payload reconstruction, deobfuscation, native and script reverse engineering, behavioral tracing, IOC extraction, and family or TTP correlation.
IDA Pro / Ghidra / YARA / C# / Python / PowerShell
B02/04
Threat research & adversarial simulation
Intelligence-driven investigation, threat emulation, adversary tradecraft analysis, detection engineering, and controlled analysis of hostile payloads across endpoint, network, web, and cloud contexts.
MITRE ATT&CK / Suricata / Sandboxing / Telemetry
C03/04
Offensive & application security
Penetration testing, red teaming, application security auditing, and security-posture validation across enterprise, web, API, and cloud environments.
Evidence-oriented control validation, audit support, privacy assessment, and control mapping across regulated and standards-driven environments.
ISO 27001/27002 / PCI DSS / GDPR / CMMC
/METHOD
FROM ARTIFACT TO ANSWER.
01Acquire
Preserve source, runtime behavior, transport evidence, and environmental context.
02Instrument
Expose code execution, browser APIs, data access, network sinks, and stage transitions.
03Reconstruct
Connect loaders, payloads, infrastructure, decisions, and observable impact.
04Operationalize
Convert findings into detections, pivots, controls, and reproducible research.
/BONUS PROTOCOL8-BIT INCIDENT RESPONSE SIMULATION
OPERATOR // NINJ4PRI3ST
HUNT THE PAYLOAD.
PORTRAIT-ID // NP-04-13ASSET VERIFIED
Malware is moving through four infrastructure segments while two hostile threat actors contest node control. Hunt the payloads, neutralize the TAs, and keep every system out of adversary hands.
[ ARACHNE // CONTAINMENT RANGE ] AWAITING EXECRUN-ID 0x8B7F
SCORE 00000MALWARE 0/12SECURE 0/4TA CONTROL 0/4TA LIVE 2/2INTEGRITY 100%
MISSION OBJECTIVES
01 // ELIMINATE 12 MALWARE PROCESSES
02 // DEFEND AND RESTORE ALL 4 NODES
03 // PERMANENTLY NEUTRALIZE BOTH TAS
04 // NEVER LET TA CONTROL EVERY NODE
MOVE WASD / ARROWS ATTACK SPACE / X SECURE NODE HOLD E