Secure Package Management
Hardening NPM and Python dependencies against software supply chain attacks and malicious packages.
Welcome ☕
We have a lot to protect and it is hard work. Brew a cup of coffee and stay a while.
Cybersecurity moves quickly, but the work still comes down to persistence, good judgment, useful tooling, and collaboration. You do not need to work at the same company to be on the same team.

What this site is about
Threat hunting, detection engineering, secure AI usage, open-source tooling, community resources, and the experiments that are useful enough to keep. The goal is to share material people can reference, critique, and improve.
Featured resources
Current work across software supply chain defense, secure AI usage, and coding-agent evaluation.
Hardening NPM and Python dependencies against software supply chain attacks and malicious packages.
A live catalog of OpenRouter ZDR-compliant AI endpoints for sensitive and confidential prompts.
Compare coding-agent configurations across benchmark performance, task cost, and token utilization.
Recent highlights & research
Hands-on notes for agentic SOC architecture, AI coding-agent isolation, local stacks, and practical automation.
Practical controls for deterministic input handling, model safety boundaries, and inference infrastructure.
The parts of developer AI that matter in practice: model value, throughput, filesystem access, shell access, and isolation.
Local LLM deployment notes covering model loading, OpenWebUI, containers, GPU access, and isolation boundaries.
Research and tooling for detecting AutoIT malware and emulating common evasion techniques.
Models, filters, and manifold pipes shared with the OpenWebUI community.
Knowledge base & resources
Guides, cheat sheets, research, community references, and project write-ups accumulated over time.
Splunk, LogScale, KQL, Sigma, YARA, Snort, Suricata, DFIR, and practical defensive engineering.
Threat hunting research, APT tracking, malware analysis, search leads, and practical intelligence workflows.
Scripts, containers, Git, Linux, package hardening, open-source projects, and engineering notes.
Local AI, agentic systems, LLM security, model analysis, and secure developer-agent workflows.
Technical interview preparation for SOC, security engineering, threat hunting, and GenAI roles.
From the start of my career I benefited from people who shared resources, cheat sheets, examples, and practical guides. This site is my attempt to keep that cycle going.