I build systems that make security teams effective.
Threat intelligence platforms, detection pipelines, and security automation. Currently building a CTI platform and threat research program from scratch. Previously: a 120TB SIEM migration, detection content, and SOC transition work.
writing
Keeping a knowledge base current in minutes instead of half a day, by never rebuilding what has not changed.
projects
- adversarial-ai-cti
A vendor-neutral STIX 2.1 representation for prompt injection and jailbreaks, so any STIX platform can ingest them.
- promptlsh
A portable similarity digest for prompt attacks, so reworded jailbreaks correlate instead of reading as unrelated items.