Independent security research
OSINT · threat intelligence · detection engineering · evidence systems · auditable AI-assisted analysis
I build research systems, investigate observable patterns in public data, and publish the methodology alongside the result. Observation, correlation, linkage, operational inference, and attribution are treated as separate evidentiary steps.
measure first. attribute last.
badBANANA Threat Observatory · live
Evidence-first threat observation with explicit source health, bounded coverage, material-change replay, and visible failure states.
LANimals
Self-hosted network intelligence, durable host and service history, and operator-reviewed change detection inside approved LAN scope.
SHENRON
Synthetic adversarial telemetry for measuring rule and correlation brittleness without portable offensive procedure.
r4b1t · source · launch
Curated random discovery through dedicated desktop and mobile shells sharing one evolving corpus, session state, and discovery engine.
GNOME Prompt Field Manual · read
Production workspace and practical reference for structured, inspectable, auditable AI-assisted work.
drift_orchestrator · research portal
Reproducible research tooling for policy drift, semantic-gradient evasion, and second-order injection against LLM safety monitors.
The rest of my public repositories are supporting experiments, narrower tools, and earlier research artifacts. The projects above are the recommended starting point.
OBSERVATION↓
CORRELATION↓
LINKAGE↓
OPERATIONAL INFERENCE↓
ATTRIBUTION
Those are separate evidentiary jumps, not interchangeable labels.
Methodological defaults
- public or explicitly authorized data sources;
- deterministic collection and analysis where practical;
- provenance-preserving evidence records;
- confidence-graded conclusions;
- explicit negative results and failed hypotheses;
- reproducible artifacts over screenshots alone;
- local-first tooling when a cloud dependency is unnecessary.
A robust pattern is not automatically a specific attribution. A repeatable result is not automatically a causal explanation.
I Pushed the badBANANA Threat Observatory Public
Why source health, bounded API coverage, stale-state labeling, and material-change evidence matter in public threat visualization.
Back to Basics: What a Forensic Investigation Can Prove — and What It Can't
Evidence boundaries, attribution discipline, and failed hypotheses.
Found 897 Fake Followers on DEV.to — Here's How I Proved It
Coordinated inauthentic behavior and evidence-driven clustering.
Second-Order Injection: Attacking the Evaluator in LLM Safety Monitors
Evaluator failure modes in LLM safety monitoring.
Threat-data integrity · detection durability · forensic methodology · coordinated inauthentic behavior · evidence ledgers · graph-based OSINT · provenance · analytical reproducibility · LLM safety evaluation · local-first research systems
SECURITY / DISCLOSURE
Private advisory reporting and PGP disclosure details.



