Personal work record

Work I have done so far.

This page is not a trophy case. It records the tools I built and the research and labs behind them. Older work stays here with a plain account of what it was.

How I work

  1. 01

    I go back to the source

    A claim is not true because it is widely shared. I look for the first source, the date, and the context.

  2. 02

    I separate evidence from interpretation

    I write down what I observed. I keep the conclusion separate. I do not sound certain where the evidence is not.

  3. 03

    I stop when the evidence ends

    I keep missing points visible. I do not treat unavailable data as if it exists to reach a stronger conclusion.

  4. 04

    A tool does not replace the analyst

    Automation should reduce repeated work. It should keep the reason for a decision visible. The final judgement stays with a person.

Work archive

Projects and earlier work

Each record points to its evidence. Source code links to the repository. Reports and working pages are listed separately when they exist.

2026

Independent research deskActiveApril 2026 - present

CSINT Research

The open research desk I built for OSINT and threat intelligence. I publish tools with their sources and keep the basis and limits of each finding visible.

Open source security toolMaintainedJuly 2026

n8n AI Security Regression Gate

Reviews risky paths in exported n8n AI workflows. It runs locally and does not send the file to an AI service. It can write JSON, Markdown, JUnit, and SARIF reports.

Fictional investigation labPublishedJuly 2026

Operation Glass Harbor

A fictional lab that brings OSINT, HUMINT, threat intelligence, and incident response into one case. Evidence, observation, and inference stay separate. Every stage has a clear deliverable.

Open source workstationMaintainedJune 2026

GOSI-Ready OSINT VM

A repeatable Ubuntu workstation for lawful OSINT practice. The installer is open and release packages ship with SHA-256 records.

Investigation workspaceActiveMay 2026 - present

Event Desk

A workspace I built to follow a live event through sources, claims, evidence, and impact records. Automation prepares drafts. The analyst makes the final decision.

Research newsletterActiveJuly 2026 - present

CSINT Field Notes

Field notes that explain one OSINT or threat intelligence method through a short exercise. The aim is not to list tools. It is to show how an investigation decision is made.

2025

Undergraduate graduation projectArchived2025

Linux malware analysis with DynamoRIO

My graduation project on analysing malware behaviour through dynamic binary instrumentation on Linux. It became one of the foundations of my interest in reverse engineering and security automation.

Archive note: A verified public source package for this work is not currently published.

2024

Training and labsActive2024 - present

Cybersecurity training and CTF labs

I prepare technical training on network security and defensive and offensive fundamentals. In CTF labs I focus on repeatable steps and clear explanations rather than the final answer alone.

2023

Mobile application securityArchived2023 - 2025

Android and iOS security research

I carried out static and dynamic analysis of Android and iOS applications. I reviewed application behaviour, API traffic, and permission models against OWASP MASVS.

2022

Malware analysisArchived2022 - 2023

Reverse engineering and binary analysis

I worked on binary analysis, fuzzing, and vulnerability research with malware samples. This period became the low-level starting point for the security tools I later built.

This record will keep growing.

I will keep discontinued experiments here as well as new work. A project does not become part of the past only when it succeeds.