Collect Secure Validate
Context reveals the gaps. Engineering closes them at scale. Risk sets the sequence. Telemetry proves the result.
Differential Triage for Windows Incident Response
A PowerShell collector and a Python merge script that diff a suspect Windows host against a known-good baseline, cutting the artifacts an analyst has to review by roughly 90 percent. No EDR, no licence, no coding required to run it.
Inside the Modern Malware Stack
Research into a live fileless info-stealer campaign: how a PowerShell dropper, trusted interpreters, and a multi-function C2 combine into a modular platform that never touches disk, and where detection still has purchase.
Threat-Enriched Log Pipeline
A modular Python pipeline that pulls logs from SQL Server, enriches every IP with VirusTotal and internal frequency context, and forwards the result to a SIEM over syslog.
The Vulnerable State of Vulnerability Management
Scanner findings tell you what exists, not what matters. How CTEM and a FAIR-inspired residual risk model reorder the queue around actual exposure, without a new tool or a renewal invoice.