Skip to content
View GnomeMan4201's full-sized avatar
🍌
🍌

Block or report GnomeMan4201

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
GnomeMan4201/README.md
badBANANA Research Collective

Independent security research
OSINT · threat intelligence · detection engineering · evidence systems · auditable AI-assisted analysis

Selected work Research method Selected writing Current interests

I build research systems, investigate observable patterns in public data, and publish the methodology alongside the result. Observation, correlation, linkage, operational inference, and attribution are treated as separate evidentiary steps.



measure first. attribute last.

Selected Work

badBANANA Threat Observatory · live
focus signal
Evidence-first threat observation with explicit source health, bounded coverage, material-change replay, and visible failure states.


LANimals
focus signal
Self-hosted network intelligence, durable host and service history, and operator-reviewed change detection inside approved LAN scope.


SHENRON
focus signal
Synthetic adversarial telemetry for measuring rule and correlation brittleness without portable offensive procedure.


r4b1t · source · launch
focus signal
Curated random discovery through dedicated desktop and mobile shells sharing one evolving corpus, session state, and discovery engine.


GNOME Prompt Field Manual · read
focus signal
Production workspace and practical reference for structured, inspectable, auditable AI-assisted work.


drift_orchestrator · research portal
focus signal
Reproducible research tooling for policy drift, semantic-gradient evasion, and second-order injection against LLM safety monitors.


The rest of my public repositories are supporting experiments, narrower tools, and earlier research artifacts. The projects above are the recommended starting point.

Research Method

OBSERVATION

CORRELATION

LINKAGE

OPERATIONAL INFERENCE

ATTRIBUTION

Those are separate evidentiary jumps, not interchangeable labels.

Methodological defaults
  • public or explicitly authorized data sources;
  • deterministic collection and analysis where practical;
  • provenance-preserving evidence records;
  • confidence-graded conclusions;
  • explicit negative results and failed hypotheses;
  • reproducible artifacts over screenshots alone;
  • local-first tooling when a cloud dependency is unnecessary.

A robust pattern is not automatically a specific attribution. A repeatable result is not automatically a causal explanation.

Selected Writing

I Pushed the badBANANA Threat Observatory Public
subject source
Why source health, bounded API coverage, stale-state labeling, and material-change evidence matter in public threat visualization.


Back to Basics: What a Forensic Investigation Can Prove — and What It Can't
subject source
Evidence boundaries, attribution discipline, and failed hypotheses.


Found 897 Fake Followers on DEV.to — Here's How I Proved It
subject source
Coordinated inauthentic behavior and evidence-driven clustering.


Second-Order Injection: Attacking the Evaluator in LLM Safety Monitors
subject source
Evaluator failure modes in LLM safety monitoring.


More writing on DEV Community

Current Interests

Threat-data integrity · detection durability · forensic methodology · coordinated inauthentic behavior · evidence ledgers · graph-based OSINT · provenance · analytical reproducibility · LLM safety evaluation · local-first research systems



SECURITY / DISCLOSURE
Private advisory reporting and PGP disclosure details.


badBANANA Research Collective — measure first, attribute last

End of File — the bad_BANANA, while producing fruit, eventually withers

Pinned Loading

  1. badBANANA-threat-observatory badBANANA-threat-observatory Public

    Evidence-first threat observatory for CISA KEV, ThreatFox, URLhaus, and MalwareBazaar with D1-backed state, provenance, replay, and policy-bound exports.

    TypeScript

  2. r4b1t r4b1t Public

    r4b1t h0L3 is a random discovery engine with 53,869+ curated URLs.StumbleUpon for OSINT and cybersecurity. No algorithm, no tracking, runs entirely in-browser. Surfaces threat intel platforms, secu…

    Python 1

  3. devto-analytics-pro devto-analytics-pro Public

    Advanced analytics for DEV.to writers - tag performance, growth trends, engagement tracking

    Python 6

  4. shenron shenron Public

    Synthetic adversarial telemetry and detection validation pipeline. Sigma rule evaluation, assumption validation, evidence discipline, HTML reports.

    Python 2

  5. zer0DAYSlater zer0DAYSlater Public

    Instrumented adversarial simulation framework for studying detection, evasion, and LLM-driven operations. Research tooling for controlled environments.

    Python 2 2

  6. Blackglass_Suite Blackglass_Suite Public

    Offline AI powered payload mutation, scoring, and stealth delivery toolkit for red teamers and experts runs in Termux & Linux.

    Shell 3 1