CYBERSECURITY RESEARCHERPT / WORLDWIDE

BREAK THE
BLACK BOX.

I investigate hostile code, adversary behavior, applications, and infrastructure, turning technical evidence into actionable security intelligence.

VIEW SELECTED SYSTEMS
MALWARE ANALYSISTHREAT INTELLIGENCEREVERSE ENGINEERINGAPPLICATION SECURITYADVERSARIAL SIMULATION

SELECTED SYSTEMS / 2024—NOW

TOOLS FOR SEEING
WHAT HIDES.

Research infrastructure built for observable, repeatable, and evidence-driven security work.
/00 — PRIMARY PLATFORM ACTIVE

CYBERSECURITY RESEARCH, ANALYSIS, INTELLIGENCE & ORCHESTRATION PLATFORM

ARACHNE

The central Brain and coordination plane of a distributed security ecosystem. ARACHNE orchestrates collection and analysis, preserves execution and evidence provenance, and turns independent security capabilities into one research environment.

BRAIN

ARACHNE is deliberately not a monolith. Major capabilities run as independently deployable platforms with their own Docker and runtime boundaries, exposing normalized data back to the central Brain.

Standard APIs allow one platform's output to become another's input. Findings, artifacts, IOCs, runtime telemetry and provenance converge through Hermes and Composite Assets before returning to the wider ARACHNE operating context.

[ ARACHNE // DISTRIBUTED RESEARCH FABRIC ]SESSION 7A3F:91C0 TRACE LIVEGRID 38.72N / 09.14W
BUS/01 RX 98.4BUS/02 TX 32.1QUEUE 0007PROV LOCKEDHASH 4A6F..91D2
01 ACQUISITION
02 ANALYSIS
03 INVESTIGATION
04 CORRELATE / ENRICH
CORE.NODE // AR-000PID 0xA91F

CENTRAL SECURITY BRAIN

ARACHNE

EXEC TRACE LINK ENRICH
root@arachne:~$ correlate --stream all --preserve-provenancesha256:4a6f81d2c90e...7b13 / fabric_rev:24.8
[ACQ.01] ONLINE

SHOGUN

INFRASTRUCTURE INTELLIGENCE

RDAP/DNS/CT7F3A:19C2
[ACQ.02] RX

ODIN EYE

EXTERNAL-SOURCE INGESTION

RSS/TG/EXT09DE:A817
[ACQ.03] TRACE

SESSIONS

RUNTIME EVIDENCE

HAR/DOM/NET3C81:4F0B
[ACQ.04] RX

CHARON

ON-CHAIN MALWARE MONITOR

EVM/RPC/JSE7A2:6C4D
[ANL.01] EXEC

JS NINJA

JAVASCRIPT REVERSE ENGINEERING

AST/CFG/IOCBB21:EF40
[ANL.02] EXEC

MOIRAI

EXTENSION ANALYSIS

CRX/HAR/DYND5A4:71E9
[ANL.03] LAB

ONYX VEIL

MOBILE APP ANALYSIS

APK/DEX/IOC11AC:88F3
[ANL.04] ONLINE

JOROGUMO

ARTIFACT / YARA INSPECTION

YARA/ROUTEA290:31DD
[INV.01] LINK

WEAVER

CASE / INVESTIGATION LAYER

CASE/TASK/LEDGER4E07:C618
[INV.02] DESIGN

SILK

ANALYST WRITEUP SYSTEM

NOTE/LINK/EXPORT0F93:EA77
[INT.01] ONLINE

HERMES

THREAT INTELLIGENCE / ENRICHMENT

IOC/STATE/PIVOTC441:08AE
[DAT.01] SYNC

COMPOSITE ASSETS

CANONICAL ENTITY / EVIDENCE GRAPH

ENTITY/EDGE/PROV9B60:2D14
> fabric.status --all // 12 nodes linked // evidence bus nominalUTC+01 // SYS.CODE ARX-4471

/SPECIALIZED PLATFORMS

INDEPENDENT RUNTIMES → UNIFIED EVIDENCE

/01 ACTIVE

Domain & infrastructure intelligence

SHOGUN

Maintains infrastructure profiles, timelines, correlations and rescans across WHOIS/RDAP, DNS, certificates, ASN, CSP and passive subdomain intelligence.

MASTERDOMAINSRDAPDNSCERTIFICATES
/02 ACTIVE

Threat-intelligence & enrichment plane

HERMES

Maintains observables, observations, state transitions and provider integrations, with direct bridges into the Brain, Shogun and JS Ninja.

THREATFOXMALTRAILOTXVIRUSTOTAL
/03 ACTIVE

JavaScript analysis workbench

JS NINJA

Tracks immutable artifact versions, findings, symbols, transformations, provenance, relationships, IOC sightings and analyst annotations.

ARTIFACTSPROVENANCETRANSFORMSFINDINGS
/04 ACTIVE

Browser-extension analysis

MOIRAI

Unpacks CRX/ZIP packages, analyzes manifests, permissions, IOCs and scripts, and executes extensions through instrumented browser workers.

CRXMANIFESTHARDYNAMIC EXECUTION
/05 ACTIVE

External-source ingestion plane

ODIN EYE

Normalizes external-source intelligence into one extensible model. RSS/Talkwalker and Telegram are the current collection lanes.

INGESTIONNORMALIZATIONRSSTELEGRAM
/06 ACTIVE

Deployment & interaction inspection

JANUS

Creates stable project URLs, configurable pages and endpoints, snapshot history, and request/observable inspection against deployed projects.

ENDPOINTSSNAPSHOTSINSPECTOROBSERVABLES
/07 ACTIVE

Artifact & YARA inspection

JOROGUMO

Routes artifact scans under Brain-managed policy, synchronizes rules, records scan history and applies pressure guardrails to dispatch.

YARAROUTINGRULE SYNCGUARDRAILS
/08 EARLY STAGE

Mobile application analysis

ONYX VEIL

Accepts APKs, runs manifest, permission and string analysis in isolated workers, and returns normalized findings through the Brain bridge.

APKISOLATED WORKERSMANIFESTFINDINGS
/09 ACTIVE

Federated execution plane

SYNAPSE

Places, leases and observes security workloads across controlled worker pools, execution classes, zones and trust boundaries.

ORCHESTRATIONLEASESWORKER POOLSFEDERATION
/10 PROTOTYPE

Evidence, assurance & audit intelligence

STRATUM

A planned layered evidence and analysis platform. Real ingestion, ClickHouse analysis and Muninn integration remain in prototype/integration phase.

EVIDENCECLICKHOUSEASSURANCEMUNINN
/11 EVOLVING

Shared security substrate

NEMEAN

Provides safe browser/UI primitives, CSP and security-header generation, and shared boundary and content-inspection contracts.

CITADELBASTIONWARDSENTINEL
/12 DESIGN

Investigation writeup system

SILK

An Obsidian-like analyst editor designed to live-link findings, IOCs, artifacts, code, browser evidence and flow results into narratives.

WRITEUPSLIVE LINKSNARRATIVESEVIDENCE
/13 ACTIVE

Egress & VPN orchestration layer

SPINNERET

Routes worker traffic through switchable NordVPN exit nodes with country/city selection, per-target-group egress, a fail-closed kill switch and live GeoIP globe.

NORDVPNEGRESSKILL SWITCHGEOIP
/14 ACTIVE

Case & investigation layer

WEAVER

Organizes case items, notes, links, timelines, tasks, observable ledgers and attached evidence into unified ARACHNE investigations.

CASESTIMELINESOBSERVABLESEVIDENCE
/15 ACTIVE

Entity & evidence graph

COMPOSITE ASSETS

Correlates canonical entities, relationships, findings, artifacts and provenance into a shared graph for enrichment and investigation pivots.

ENTITIESRELATIONSHIPSPROVENANCECORRELATION
/16 ACTIVE

On-chain malware & EtherHiding monitor

CHARON

Scans live and historical blockchain activity for smart-contract payloads, validates and classifies extracted JavaScript, and routes detections into JS Ninja, Spinneret and ARACHNE workflows.

ETHERHIDINGEVM CHAINSJS PAYLOADSDETECTIONS
/PROFILEANALYST + RESEARCHER

OPERATING PRINCIPLE

OBSERVATION
BEFORE ASSUMPTION.

I work where malicious code, applications, infrastructure, and evidence meet. The objective is not simply to label an artifact or identify a weakness, but to reconstruct adversary behavior, validate impact, and produce defensible security conclusions.

My work spans offensive and defensive security, combining reverse engineering, penetration testing, adversarial simulation, and intelligence-led investigation with evidence-based auditing across enterprise and cloud environments.

A01/04

Malware analysis & reverse engineering

Threat analysis, layered payload reconstruction, deobfuscation, native and script reverse engineering, behavioral tracing, IOC extraction, and family or TTP correlation.

IDA Pro / Ghidra / YARA / C# / Python / PowerShell
B02/04

Threat research & adversarial simulation

Intelligence-driven investigation, threat emulation, adversary tradecraft analysis, detection engineering, and controlled analysis of hostile payloads across endpoint, network, web, and cloud contexts.

MITRE ATT&CK / Suricata / Sandboxing / Telemetry
C03/04

Offensive & application security

Penetration testing, red teaming, application security auditing, and security-posture validation across enterprise, web, API, and cloud environments.

Penetration Testing / Red Teaming / AppSec / APIs / Cloud
D04/04

Security assurance & compliance

Evidence-oriented control validation, audit support, privacy assessment, and control mapping across regulated and standards-driven environments.

ISO 27001/27002 / PCI DSS / GDPR / CMMC

/METHOD

FROM ARTIFACT
TO ANSWER.

  1. 01Acquire

    Preserve source, runtime behavior, transport evidence, and environmental context.

  2. 02Instrument

    Expose code execution, browser APIs, data access, network sinks, and stage transitions.

  3. 03Reconstruct

    Connect loaders, payloads, infrastructure, decisions, and observable impact.

  4. 04Operationalize

    Convert findings into detections, pivots, controls, and reproducible research.

OPERATOR // NINJ4PRI3ST

HUNT THE
PAYLOAD.

Pixel-art portrait of NINJ4PRI3ST, a hooded cyber operator holding a blade and security seal
PORTRAIT-ID // NP-04-13ASSET VERIFIED

Malware is moving through four infrastructure segments while two hostile threat actors contest node control. Hunt the payloads, neutralize the TAs, and keep every system out of adversary hands.

[ ARACHNE // CONTAINMENT RANGE ] AWAITING EXECRUN-ID 0x8B7F
SCORE 00000MALWARE 0/12SECURE 0/4TA CONTROL 0/4TA LIVE 2/2INTEGRITY 100%
MISSION OBJECTIVES

01 // ELIMINATE 12 MALWARE PROCESSES

02 // DEFEND AND RESTORE ALL 4 NODES

03 // PERMANENTLY NEUTRALIZE BOTH TAS

04 // NEVER LET TA CONTROL EVERY NODE

MOVE WASD / ARROWS
ATTACK SPACE / X
SECURE NODE HOLD E