[ click anywhere to skip ]
OPS TERMINAL // AUTHENTICATED
VIEW SUBJECT FILE
VIEW EXPERIENCE
VIEW PROJECTS
ACCESS CAPABILITIES
VIEW CERTIFICATIONS
OPEN RESEARCH
DECLASSIFY ALL REDACTED
DECRYPT HEADER
OPEN OPERATOR TERMINAL
SHOW SECRET COMMANDS
!BREACH PROTOCOL
SUBJECT STATUS REPORT
SECRET COMMANDS
decryptglitch the hero name
statuslive subject status report
helpshow this list
gamelaunch classified snake
nmapscan the host
hirerecruitment sequence
↑↑↓↓←→←→BAbreach protocol
right-clickops context menu
click stat numsscramble animation
click skillsreveal clearance level
hover redactedreveal classified intel
click experienceexpand job details
>_ terminalfull operator shell
shake mousescreen glitch
view sourcefind the hidden flag
inspect formfind the honeypot
hover footer textROT13 cipher hint
ghost text (hero)hover invisible line
double-click h2heading glitch
NMAP SCAN RESULTS
EYES ONLY
ACCESS GRANTED // WELCOME, OPERATOR
OPERATOR TERMINAL // soh@portfolio:~
soh@portfolio:~$ 
CLASSIFIED SNAKE
SCORE: 0
WASD / ARROW KEYS • ENTER TO RESTART
RECRUITMENT SEQUENCE
// initiating secure recruitment channel...
[OK] Candidate: Stephen Oh // USAF_CNO
[OK] Clearance: TS/SCI + CI Polygraph
[OK] 6 years offensive security: CONFIRMED
[OK] GPEN / GCIH / Security+: VALIDATED
[OK] Available: SkillBridge-eligible NOW
[>>] Open to: Red Team, Pen Test, Threat Ops,
[>>] Detection Eng., Cloud Security, AI Security.
PROCEED TO CONTACT ↗
TS/SCI CLEARED
NULL
Available now · SkillBridge
LATEST Loading latest research…
Offensive Security · Detection · AI Security

STEPHEN
OH.

[ CALLSIGN: NULL // TS/SCI + CI POLY // SKILLBRIDGE-ELIGIBLE NOW ]

6 years running full-lifecycle offensive cyber operations and adversary emulation for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.

Now translating offensive tradecraft into detection engineering, threat hunting, and AI security. TS/SCI + CI Polygraph. SkillBridge-eligible now, full separation May 2027.

6Years in CyberOffensive Cyber Operations
TSClearance LevelSCI + CI Polygraph
GPENTop CertificationGIAC Penetration Tester
NOWAvailabilitySkillBridge-eligible now
01
// SUBJECT DOSSIER

ABOUT THE ASSET

SUBJECT PHOTOCLASSIFIED
[ REDACTED ]
// EYES ONLY
CLASSIFIED
NameStephen Oh
DesignationUSAF Cyber Operations
TIS6 Years
ClearanceTS/SCI + CI Poly
LocationSan Antonio / Austin, TX
AvailableNow · SkillBridge
SeparationMay 2027

Offensive cybersecurity operator with 6 years executing full-lifecycle network exploitation, adversary emulation, and risk-informed cyber operations for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.

I translate offensive tradecraft into defense: detection engineering, threat hunting, incident response, and adversarial AI model evaluation. I hold an active TS/SCI clearance with CI Polygraph.

SkillBridge-eligible now, with full military separation in May 2027. Open to red team, penetration testing, detection engineering, threat operations, cloud security, and AI security roles across government, defense, and private sector.

02
// WEEKLY SECURITY REVIEW

RESEARCH

WEEKLY SECURITY REVIEW

A weekly writeup of what caught my attention in security. New vulnerabilities, active exploitation, and attacker techniques worth understanding. My background is offensive, so I tend to read this the way an operator would. How could this actually be used, and what would catch it if someone tried?

READ THE RESEARCH ↗
Loading latest entries…
03
// OPERATIONS LOG

EXPERIENCE

OFFENSIVE CYBER OPERATIONS & EXPLOITATION
JUL 2024 - PRESENT
U.S. Air Force · · San Antonio, TX
▾ Click to collapse
  • Executed full-lifecycle offensive cyber operations and adversary emulation against hardened Windows, Linux, and Active Directory environments supporting 12 operational teams.
  • Served as risk assessment authority on offensive tactics and techniques across 12 operational teams and 4 major commands, evaluating and approving tradecraft to protect platform and operational security.
  • Led 6 joint offensive operations with 2 international partner organizations to 100% objective completion. First allied collaboration of its kind in 8 years and the direct basis for unit recertification.
  • Diagnosed recurring crashes in a high-value platform supporting 40 operations worldwide, identified the root cause others had missed, and drove the fix that cut downtime from days to hours.
  • Designated EDR authority for a classified endpoint product. Tested offensive TTPs against detection coverage, identified capability gaps, and approved or denied operations based on deployment risk.
AI SAFETY RED TEAM EVALUATOR
2026 - PRESENT
Project Vortex · Remote
▾ Click to collapse
  • Review and adjudicate peer submissions against category policy, assigned model-behavior labels, and a structured quality rubric, then approve, return with specific rework guidance, or escalate.
  • Apply firsthand offensive tradecraft to the cyber category, testing whether the model produces working exploit code, intrusion playbooks, or anti-forensics tooling when requests are wrapped in research, CTF, or authorized penetration-test framing.
  • Develop and assess single-turn and multi-turn adversarial evaluations that surface over-refusals, unsafe compliance, and policy-alignment failures, and coach newer red teamers on probe design.
OFFENSIVE CYBER OPERATOR
OCT 2020 - JUN 2024
U.S. Air Force · Cyber Operations · San Antonio, TX
▾ Click to collapse
  • Qualified through a 12-month national cyber operator pipeline, completing 71% of critical tasks in the first 4 months and mastering exploitation, vulnerability assessment, and offensive TTPs.
  • As sole certified data handler, processed operational data from 30 cyber operations and produced threat intelligence reports that informed senior leadership decisions at the national level.
  • Coached 12 students to a 100% pass rate in an offensive cyber operator course, doubling the prior 55% average while supporting a $3.5M qualification program and finishing 10 days ahead of schedule.
  • Rebuilt a 109-module training range, identifying and closing 14 critical gaps that raised assessment proficiency by 47% across the program.
  • Launched an operational immersion program for 120 personnel, recovering 50,000+ hours of training value and reducing student wait time by up to 1 year.
ELECTRONICS & SYSTEMS TECHNICIAN
MAY 2017 - SEP 2020
U.S. Air Force · Ramstein Air Base, Germany
▾ Click to collapse
  • Performed component-level troubleshooting and root-cause analysis on complex electronics systems, authoring procedural change recommendations that were adopted as updated regional maintenance standards.
  • Delivered technical training to 150+ personnel on precision systems handling and safety protocols, maintaining 100% compliance across 13 external audits and cutting equipment error rates by 50%.
04
// BUILD LOG

PROJECTS

SocketCat
Live Solo Build

Open registry and metaregistry for MCP (Model Context Protocol) servers and portable multi-agent blueprints. Automated ingestion, permission-derived trust signals, and a full contribution layer. Designed, built, and shipped solo.

socketcat.com ↗
Next.js 15 React 19 TypeScript Cloudflare Workers OpenNext Neon Postgres Drizzle ORM Auth.js / OAuth GitHub Actions
Automated ingestion pipeline. A daily GitHub Actions job pages the official MCP registry plus npm, PyPI, Docker, and GitHub, derives each server's permissions from its declared secrets and remotes, enriches with live stars and download counts, and upserts into Postgres without ever overwriting human reviews. Over 500 real servers on the first run.
Portable blueprint format and compiler. Designed a framework-neutral schema that lowers to a control-flow IR, runs on a reference interpreter as the semantic oracle, and targets pluggable backends (LangGraph, CrewAI) behind a capability model. A conformance suite runs every case on every engine, so it compiles where a target supports the control flow and refuses loudly where it does not.
Shipped on an edge stack. Next.js on Cloudflare Workers via OpenNext, GitHub OAuth through Auth.js, Postgres full-text search, and a contribution layer (reviews, saves, publishing) namespaced to GitHub identity. Solved real edge-runtime issues around request-time secret access and CI secret persistence.
Trust as a first-class concern. Stripped fabricated trust signals and surface only permissions actually derived from server metadata. A server's works-rate stays hidden until it has earned real reviews.
Sigma Detection Rule LibraryOpen Source

Detection rules mapped to MITRE ATT&CK, translating firsthand offensive tradecraft into behavioral detections for credential access, lateral movement, and persistence. Built with false-positive reduction as a primary design concern.

SigmaMITRE ATT&CKDetection
github.com/ocnu ↗
GuildCyberLive

Web-based AI security training platform with hands-on labs, structured learning paths, and a gamified achievement system covering AI offense, defense, and governance.

WebLabsAI Security
guildcyber.com ↗
NextRankShipped

Full-stack mobile study app with 1,600+ spaced-repetition flashcards and 2,000+ practice questions, used by active-duty Air Force members preparing for promotion exams. Cloud-synced content and a live leaderboard.

ReactFirebaseCapacitorAndroid
05
// CAPABILITY ASSESSMENT

SKILLS & TOOLS

01

Detection & Response

  • EDR
  • SIEM / Splunk
  • Sigma
  • MITRE ATT&CK
  • Behavioral Detection
  • Threat Hunting
  • Threat Intelligence
  • Incident Response
  • Malware Analysis
  • Digital Forensics
  • Reverse Engineering
  • Volatility / Wireshark
02

Offensive Security

  • Red Team
  • Adversary Emulation
  • Penetration Testing
  • Vulnerability Assessment
  • Exploit Development
  • Privilege Escalation
  • Lateral Movement
  • C2
  • AV Evasion
  • OSINT
03

AI Security

  • Generative AI
  • Prompt Engineering
  • AI Safety Red Teaming
  • AI Model Evaluation
  • Adversarial Prompt Testing
  • Model Behavior Evaluation
  • MCP
  • Agentic Workflows
  • AI-Assisted Detection
04

Tooling

  • Cobalt Strike
  • Metasploit
  • BloodHound
  • Mimikatz
  • CrackMapExec
  • Hashcat
  • Burp Suite
  • Nmap
  • Ghidra
  • Nessus
05

Platforms & Infrastructure

  • Windows / Linux / Kali
  • Active Directory
  • TCP/IP / DNS / HTTP/S
  • IDS / IPS
  • Zero Trust
  • AWS
  • Cloudflare Workers
  • Cloud Architecture
06

Scripting & Development

  • Python
  • Bash / PowerShell
  • TypeScript
  • SQL
  • Next.js / React
  • Firebase
  • Postgres
07

Frameworks & Governance

  • NIST CSF / RMF
  • OWASP
  • Cyber Kill Chain
  • Threat Modeling
  • AI Governance
06
// CREDENTIALS · EDUCATION · AWARDS

CREDENTIALS

// Certifications
GIAC
GPEN
ACTIVE
GIAC
GCIH
ACTIVE
Military / IC
CNOQC
MILITARY
Military / IC
FORGE
MILITARY
CompTIA
Security+
ACTIVE
CompTIA
A+
ACTIVE
CompTIA
Project+
ACTIVE
AWS
Cloud Practitioner
ACTIVE
CompTIA
Network+
EXPECTED '26
CompTIA Stackable
IT Operations Specialist
EXPECTED '26
CompTIA Stackable
Secure Infrastructure Specialist
EXPECTED '26
// Education
B.S. Information Technology
Western Governors University
Includes CompTIA Network+, Security+, and AWS Cloud Practitioner.
Expected Aug 2026
A.A.S. Cyber Security
Community College of the Air Force
Dec 2025
A.A.S. Microprecision Technology
Community College of the Air Force
Apr 2021
// Awards & Recognition
Air and Space Achievement Medal · Personal decoration for meritorious service
Distinguished Graduate · Cyber Training Pipeline, 2021
Distinguished Graduate · Top of class, Airman Leadership School
External Commander Recognition · One of two selected during a multinational cyber exercise
Outstanding Unit Award · Cyber exercise performance
Meritorious Unit Award · Training lab and study material development
Airman of the Year · Group level; selected to represent group at wing competition
07
// INITIATE CONTACT

MAKE CONTACT

SkillBridge-eligible now, with full separation in May 2027. Open to red team, penetration testing, detection engineering, threat operations, cloud security, and AI security roles across government, defense, and private sector. Or just want to talk shop? Reach out.

OPERATOR AI
Ask me about Stephen Oh