Projects
Tools, field manuals, and infrastructure I build and run for threat intelligence, hunting, and detection work.
TrendPulse
OperationalThe collection and production pipeline behind the reports on this site: source collection, scoring, drafting, and a verification gate that checks every indicator, CVE, and citation against the fetched source text before anything is published.
CTI Threat Hunt Map
LiveAn ATT&CK v19.1 hunt reference: 375 hunts and 225 LOLBins with copy-ready Splunk, Elastic, and Corelight queries, cross-linked to 212 threat actors. Runs entirely in the browser.
Windows Event Log Field Manual
LiveAdvanced Windows Event Log Analysis (AWELA): 77 sections covering triage playbooks, process and system baselines, attack detection, and event references for Security, System, PowerShell, and Sysmon logs. Every query in Splunk SPL.
Honeypot Sensor Network
OperationalA T-Pot deployment running 30+ honeypot services on cloud infrastructure since March 2026. It collects attack telemetry and payloads for analysis and future malware reports.
HackRF Spectrum Sentry
In developmentA baseline hunt applied to the RF spectrum. It sweeps with a HackRF, learns a baseline, and flags persistent anomalies for triage. Receive-only by design.