Projects

Things I've built and shipped.

A mix of frameworks, automations, tools, and experiments — some anonymized due to client confidentiality, others open for the community.

Selected work

Projects

PROJECT / 01active

Early Warning Operations Model

A practical framework for designing national and sector-scale cyber early warning systems. Covers detection architecture, alert routing, stakeholder mapping, and operating models that survive lean staffing. Drawn from engagements with national CERTs across Central and South Asia.

Framework
Tools & utilities

Tooling

building

cti-triage-filter

A set of filtering rules and scoring logic for turning raw threat intelligence feeds into actionable alerts. Designed for teams with more feeds than analysts.

AutomationCTI
experiment

agent-watchdog

An experimental AI agent for first-pass alert triage in CSIRT operations. Human-in-the-loop by design. Not production-ready.

AI AgentExperiment
Free resources

Free things I point people to before anything paid.

Have I Been PwnedFree

Have I Been Pwned — free breach monitoring for national CERTs

Troy Hunt gives national CERTs and government CSIRTs free access to query and monitor their government domains against billions of breached credentials — domain search via API, with alerts when new breaches hit. More than 45 governments onboarded, from Bangladesh to Bhutan. If you run a national CSIRT and you are not on the list, that gap is fixable in one email.

See the government onboardings
ShadowserverFree

Shadowserver — free daily reports on your own network

Before buying any threat feed, sign up for this. Shadowserver emails a free daily report on your own ASN or IP ranges: exposed attack surface (open RDP, Elasticsearch, MongoDB) plus malware and botnet activity leaving your network. 90+ report types, by email or API. No charge — it is a nonprofit, and national CERTs can get country-level reports. The first thing I set up with any new CERT.

Request free reports
Open work

Want to collaborate?

I'm always interested in collaborating with practitioners who are building in the early warning, CTI, and CSIRT space. If you have a project that aligns, get in touch.

Current open questions I'm exploring: How do lean CSIRTs scale triage without scaling headcount? What does effective public-private coordination actually look like in practice? How can AI agents augment (not replace) human judgment in security operations?