Security researcher focused on privacy-minded tools, cloud application security, API/WAF controls, and AI agent trust boundaries.
I build open tools that put you back in control of your data and desktop, plus labs that show how agents and detections fail under real attack pressure — then harden and retest.
| Project | What it is |
|---|---|
| win-debloat | Privacy-first Windows hygiene — unhook OneDrive Desktop Known Folder Move, optional OneDrive uninstall, light Appx cleanup. Defender and Windows Update stay on. |
| ai-security-architecture | Threat models, trust boundaries, secure RAG/agent design, and architecture review exercises. |
| detection-engineering-lab | Wazuh + Sysmon detections mapped to ATT&CK, with IaC and validation workflows. |
| AzureHoneyNet | Azure exposure lab — Sentinel telemetry, KQL detections, and the limits of before/after measurement. |
Understand the architecture → reproduce the failure → harden the control → make the test repeatable. Prefer small, auditable tools over opaque “debloat” scripts that gut your security stack.
Secure Cloud Academy — practitioner-built CompTIA study packs (Security+ live).
Python · PowerShell · Terraform · FastAPI · AWS · Azure · GitHub Actions





