I investigate how software crosses trust boundaries—and build tools that make security research more practical, accountable, and useful.
I'm an independent, self-taught security researcher and developer. I learn by building, reading source, testing assumptions, and working with maintainers to turn findings into focused fixes.
My research spans authorization failures, sandbox escapes, parsers and deserialization, payment integrations, and kernel protocol and permission handling. I use AI-assisted development alongside hands-on source analysis and human review.
My public work includes 34 CVEs, 17 repository GitHub Security Advisories, and four accepted Linux mainline fixes. The CVE total includes two Linux kernel findings. My kernel contributions include two authored SCTP patches and two KSMBD findings credited through Reported-by, with nine verified stable backports across those fixes.
I've contributed research affecting projects including vm2, PyJWT, Apache Fory, TypeBox, isomorphic-git, fast-xml-parser, libheif, KEDA, and Yamcs, alongside WordPress plugins and payment integrations.
| Portfolio | What you'll find |
|---|---|
| CVE & GHSA research | Published disclosures, root-cause analysis, affected versions, and remediation |
| Linux kernel contributions | Accepted patches, reported findings, mainline commits, and stable backports |
An operator-driven security research workbench for scoped investigations, evidence retention, reproducible analysis, and remediation review. I'm building it around deliberate scope and human-controlled disclosure decisions.
A local-first AI safety project for families, with a visible Windows agent, a parent-owned backend, local analysis, encrypted evidence storage, and a parent review dashboard. It's currently an alpha / developer preview built to support review and conversation, not replace human judgment.
- ThreatHive — defensive honeypot telemetry and controlled lab analysis; public alpha.
- Dashburg — a local-first control center for agents, nodes, and AI infrastructure.
I'm interested in collaborating with maintainers, security researchers, and builders working on open-source security and practical tooling.
LinkedIn · Security research · Linux contributions · SecHive.ai
Public research totals updated October 2, 2026.




