This is the deep end: how my projects are built, how I run infrastructure, and what my security research actually involves. Plain language where possible, precise terms where they matter.
Default stack: TypeScript + Next.js + PostgreSQL, deployed on Linux servers I administer myself (Docker, Nginx, automated TLS). Python for data pipelines and security tooling. AI features stay local-first where privacy matters — DuckDB in the browser, on-device inference, secret redaction before any model call.
Two principles: deterministic tools are authoritative, AI is advisory — and data stays local unless there’s a reason to move it. Each project page documents the specific architecture and tradeoffs.
All offensive work below happened in isolated lab environments I control — never against systems I don’t own. The point of each exercise: understand the failure, then write the fix.
Demonstrated remote code execution vulnerabilities in unpatched legacy SMBv1 services in an isolated virtual lab. Extracted NTLM hashes and audited Active Directory password complexity compliance.
Metasploit
Hashcat
Mimikatz
Active Directory
SMBv1
The full report walks through every command — recon, exploitation, credential cracking — and ends with a prioritized remediation table.
Target: Global Malicious IP Feeds Method: Automated Threat Ingestion & Geolocation
Ingested and normalized threat intelligence from public blocklists, resolved threat origins with MaxMind databases, and visualized active attack infrastructure on a 3D WebGL globe.
Python
MaxMind GeoIP
React Three Fiber
Firestore
The full report walks through every command — recon, exploitation, credential cracking — and ends with a prioritized remediation table.
WALKTHROUGH ✦FIELD NOTES ✦OPEN SOURCE ✦READ THE REAL THING ✦WALKTHROUGH ✦FIELD NOTES ✦OPEN SOURCE ✦READ THE REAL THING ✦WALKTHROUGH ✦FIELD NOTES ✦OPEN SOURCE ✦READ THE REAL THING ✦WALKTHROUGH ✦FIELD NOTES ✦OPEN SOURCE ✦READ THE REAL THING ✦
WRITEUP Nº 001
THM-MD2PDF WALKTHROUGH
My only published technical writeup — and it meets the bar I hold everything else to: a complete TryHackMe walkthrough with every command, every finding and every fix, written to be reproduced step by step in an isolated lab.