CSINT Research
The open research desk I built for OSINT and threat intelligence. I publish tools with their sources and keep the basis and limits of each finding visible.
Personal work record
This page is not a trophy case. It records the tools I built and the research and labs behind them. Older work stays here with a plain account of what it was.
A claim is not true because it is widely shared. I look for the first source, the date, and the context.
I write down what I observed. I keep the conclusion separate. I do not sound certain where the evidence is not.
I keep missing points visible. I do not treat unavailable data as if it exists to reach a stronger conclusion.
Automation should reduce repeated work. It should keep the reason for a decision visible. The final judgement stays with a person.
Work archive
Each record points to its evidence. Source code links to the repository. Reports and working pages are listed separately when they exist.
The open research desk I built for OSINT and threat intelligence. I publish tools with their sources and keep the basis and limits of each finding visible.
Reviews risky paths in exported n8n AI workflows. It runs locally and does not send the file to an AI service. It can write JSON, Markdown, JUnit, and SARIF reports.
A fictional lab that brings OSINT, HUMINT, threat intelligence, and incident response into one case. Evidence, observation, and inference stay separate. Every stage has a clear deliverable.
A repeatable Ubuntu workstation for lawful OSINT practice. The installer is open and release packages ship with SHA-256 records.
A workspace I built to follow a live event through sources, claims, evidence, and impact records. Automation prepares drafts. The analyst makes the final decision.
Field notes that explain one OSINT or threat intelligence method through a short exercise. The aim is not to list tools. It is to show how an investigation decision is made.
My graduation project on analysing malware behaviour through dynamic binary instrumentation on Linux. It became one of the foundations of my interest in reverse engineering and security automation.
Archive note: A verified public source package for this work is not currently published.
I prepare technical training on network security and defensive and offensive fundamentals. In CTF labs I focus on repeatable steps and clear explanations rather than the final answer alone.
I carried out static and dynamic analysis of Android and iOS applications. I reviewed application behaviour, API traffic, and permission models against OWASP MASVS.
I worked on binary analysis, fuzzing, and vulnerability research with malware samples. This period became the low-level starting point for the security tools I later built.
I will keep discontinued experiments here as well as new work. A project does not become part of the past only when it succeeds.