01
Emerging Threats
Expertise in zero-day exploitation and edge device security, including high-profile campaigns targeting Ivanti and Citrix infrastructure.
Threat Intelligence
Principal Threat Analyst | Emerging Threats • Automation • AI-Driven Defense
Analyzing high-impact threats at scale. Expert in major incident response, software supply chain integrity, and the intersection of AI and Cyber Threat Intelligence (CTI).
Core Specialties
Research designed to move quickly from investigation into defender action, with emphasis on high-impact intrusions and scalable analysis systems.
01
Expertise in zero-day exploitation and edge device security, including high-profile campaigns targeting Ivanti and Citrix infrastructure.
02
Building scalable systems to detect, analyze, and disrupt global threat actor infrastructure with faster and more consistent defensive workflows.
03
Identifying malicious NPM and PyPI packages, tracing upstream compromise, and surfacing abuse before it cascades across the software ecosystem.
04
Technical lead for globally significant intrusions involving APT44, Turla, and Sandworm, with emphasis on fast-moving operational response.
Open Source
Open-source frameworks for decoding, scoring, and extracting malicious document streams — built when maldocs were routinely missed by commercial AV. QuickSand is the current analysis framework; Cryptam and PDFExaminer are its predecessors.
Python analysis framework for Office documents, PDFs, MIME/email, and more. Decodes streams, scans with Yara, and scores risk for faster triage.
QuickSand overview GitHubTry QuickSand without installing anything. Upload a suspected document and get stream extraction, Yara matches, and a risk score.
Open scannerOriginal web scanners from 2009 for embedded executables and PDF exploit analysis. Both evolved into QuickSand.
Read the storyFeatured Reports
Selected work spanning supply chain compromise, major incidents, and state-backed intrusion activity.
Featured from the current archive as a recent high-impact publication.
Read featured reportResearch Archive
Showing 13 reports
Emerging Threats
Major Incident
Major Incident
Supply Chain
Major Incident
APT / Infrastructure
Emerging Threats
Major Incident / OT
Ransomware
Infrastructure
Cloud Security
Ransomware
Supply Chain
No reports match the current filter.
Connect
LinkedIn is the primary channel for professional conversation and current updates.
Visit LinkedIn