6 years running full-lifecycle offensive cyber operations and adversary emulation for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.
Now focused on AI and agentic attack surface: adversarial evaluation of production models, prompt injection and jailbreak analysis, and measuring how detection coverage holds up against real attacker TTPs. SkillBridge candidate, separating May 2027.
Offensive cybersecurity operator with 6 years executing full-lifecycle network exploitation, adversary emulation, and risk-informed cyber operations for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.
Now focused on the AI and agentic attack surface: adversarial evaluation of production models, prompt injection and jailbreak analysis, malicious code classification, and measuring how detection coverage holds up against real attacker TTPs. I hold an active TS/SCI clearance with CI Polygraph.
SkillBridge candidate, with full military separation in May 2027. Open to AI security research, red team, adversarial evaluation, detection engineering, and threat operations roles across government, defense, and private sector.
A weekly writeup of what caught my attention in security. New vulnerabilities, active exploitation, and attacker techniques worth understanding. My background is offensive, so I tend to read this the way an operator would. How could this actually be used, and what would catch it if someone tried?
Open registry and metaregistry for MCP (Model Context Protocol) servers and portable multi-agent blueprints. Automated ingestion, permission-derived trust signals, and a full contribution layer. Designed, built, and shipped solo.
socketcat.com ↗AI red team platform. Live, attackable AI targets with 15 graded challenges covering prompt injection and agentic tool abuse, mapped to the OWASP LLM Top 10 and MITRE ATLAS and graded on whether the attack lands. In front of the targets sits a two-stage prompt injection guard: a heuristic filter, then a logistic regression classifier over bge-small embeddings, with retraining gated on F1.
guildcyber.com ↗Red team and remediation of this site's own chat assistant. Found that the chat proxy accepted a client-supplied system prompt, an open model proxy on my API key that bypassed every guardrail at the trust boundary. Remediated by moving the prompt and policy server-side and adding rate limiting and input validation.
Detection rules mapped to MITRE ATT&CK, translating firsthand offensive tradecraft into behavioral detections for credential access, lateral movement, and persistence. Built with false-positive reduction as a primary design concern.
github.com/ocnu ↗SkillBridge candidate, separating May 2027. Open to AI security research, red team, adversarial evaluation, detection engineering, and threat operations roles across government, defense, and private sector. Or just want to talk shop? Reach out.