Security research
and open-source tooling.

I build tools that find vulnerabilities in CI/CD pipelines, supply chains, and cloud infrastructure. When I find something interesting, I write about it here.

Recent Research

Projects