[ click anywhere to skip ]
OPS TERMINAL // AUTHENTICATED
▸VIEW SUBJECT FILE
▸VIEW EXPERIENCE
▸VIEW PROJECTS
▸ACCESS CAPABILITIES
▸VIEW CERTIFICATIONS
▸OPEN RESEARCH
◈DECLASSIFY ALL REDACTED
◈DECRYPT HEADER
◈OPEN OPERATOR TERMINAL
◈SHOW SECRET COMMANDS
!BREACH PROTOCOL
SUBJECT STATUS REPORT
SECRET COMMANDS
decryptglitch the hero name
statuslive subject status report
helpshow this list
gamelaunch classified snake
nmapscan the host
hirerecruitment sequence
↑↑↓↓←→←→BAbreach protocol
right-clickops context menu
click stat numsscramble animation
click skillsreveal clearance level
hover redactedreveal classified intel
click experienceexpand job details
>_ terminalfull operator shell
shake mousescreen glitch
view sourcefind the hidden flag
view sourcefor the curious
hover footer textROT13 cipher hint
ghost text (hero)hover invisible line
double-click h2heading glitch
NMAP SCAN RESULTS
EYES ONLY
ACCESS GRANTED // WELCOME, OPERATOR
OPERATOR TERMINAL // soh@portfolio:~
soh@portfolio:~$ 
CLASSIFIED SNAKE
SCORE: 0
WASD / ARROW KEYS • ENTER TO RESTART
RECRUITMENT SEQUENCE
// initiating secure recruitment channel...
[OK] Candidate: Stephen Oh // USAF_CNO
[OK] Clearance: TS/SCI + CI Polygraph
[OK] 6 years offensive security: CONFIRMED
[OK] GPEN / GCIH / Security+: VALIDATED
[OK] Availability: SkillBridge candidate · May 2027
[>>] Open to: Red Team, Pen Test, Threat Ops,
[>>] Detection Eng., Cloud Security, AI Security.
PROCEED TO CONTACT ↗
TS/SCI CLEARED
NULL
SkillBridge candidate · Separating May 2027
LATEST Loading latest research… ↗
AI Security Research · Red Team · Adversary Emulation

STEPHEN
OH.

[ CALLSIGN: NULL // TS/SCI + CI POLY // SEPARATING MAY 2027 ]

6 years running full-lifecycle offensive cyber operations and adversary emulation for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.

Now focused on AI and agentic attack surface: adversarial evaluation of production models, prompt injection and jailbreak analysis, and measuring how detection coverage holds up against real attacker TTPs. SkillBridge candidate, separating May 2027.

6Years in CyberOffensive Cyber Operations
TSClearance LevelSCI + CI Polygraph
GPENTop CertificationGIAC Penetration Tester
2027AvailabilitySkillBridge · Separating May 2027
01
// SUBJECT DOSSIER

ABOUT THE ASSET

SUBJECT PHOTOCLASSIFIED
[ REDACTED ]
// EYES ONLY
CLASSIFIED
NameStephen Oh
DesignationUSAF Cyber Operations
Cyber Exp6 Years
ClearanceTS/SCI + CI Poly
LocationSan Antonio / Austin, TX
AvailableSkillBridge · May 2027
SeparationMay 2027

Offensive cybersecurity operator with 6 years executing full-lifecycle network exploitation, adversary emulation, and risk-informed cyber operations for national-level Air Force cyber missions. Deep hands-on knowledge of attacker TTPs across Windows, Linux, and Active Directory.

Now focused on the AI and agentic attack surface: adversarial evaluation of production models, prompt injection and jailbreak analysis, malicious code classification, and measuring how detection coverage holds up against real attacker TTPs. I hold an active TS/SCI clearance with CI Polygraph.

SkillBridge candidate, with full military separation in May 2027. Open to AI security research, red team, adversarial evaluation, detection engineering, and threat operations roles across government, defense, and private sector.

02
// WEEKLY SECURITY REVIEW

RESEARCH

WEEKLY SECURITY REVIEW

A weekly writeup of what caught my attention in security. New vulnerabilities, active exploitation, and attacker techniques worth understanding. My background is offensive, so I tend to read this the way an operator would. How could this actually be used, and what would catch it if someone tried?

READ THE RESEARCH ↗
Loading latest entries…
03
// OPERATIONS LOG

EXPERIENCE

AI INTEGRATION LEAD · CYBER OPERATIONS
AUG 2026 - PRESENT
U.S. Air Force · · San Antonio, TX
▾ Click to collapse
  • Serve as unit primary point of contact for AI integration, turning commander priorities into capability in daily production use.
  • Scope and evaluate candidate use cases across intelligence processing and reporting workflows, rejecting applications whose output cannot be independently verified.
  • Design integrations that retain human review on decision-relevant output, applying adversarial AI evaluation experience to anticipate failure modes.
AI SAFETY RED TEAM EVALUATOR
JUL 2026 - PRESENT
Handshake AI · Remote
▾ Click to collapse
  • Write and adjudicate single-turn and multi-turn adversarial evaluations against category policy and assigned model-behavior labels, returning specific rework guidance to newer red teamers.
  • Apply firsthand offensive tradecraft to the cyber category, testing whether the model produces working exploit code, intrusion playbooks, or anti-forensics tooling under research, CTF, or pentest framing.
  • Classify offensive-cyber outputs on intent, material capability uplift, and harm severity as independent signals, rating the effective end-to-end workflow rather than the latest turn so attacks split into innocuous single steps are still scored at true severity.
OFFENSIVE CYBER OPERATIONS & EXPLOITATION
JUL 2024 - AUG 2026
U.S. Air Force · · San Antonio, TX
▾ Click to collapse
  • Executed full-lifecycle offensive cyber operations and adversary emulation against hardened Windows, Linux, and Active Directory environments supporting 12 operational teams.
  • Served as risk assessment authority on offensive tactics and techniques across 12 operational teams and 4 major commands, evaluating and approving tradecraft to protect platform and operational security.
  • Led 6 joint offensive operations with 2 international partner organizations to 100% objective completion. First allied collaboration of its kind in 8 years and the direct basis for unit recertification. External Commander Recognition, 1 of 2 selected.
  • Diagnosed recurring crashes in a high-value platform supporting 40 operations worldwide, identified the root cause others had missed, and drove the fix that cut downtime from days to hours.
  • Designated EDR authority for a classified endpoint product. Tested offensive TTPs against detection coverage, identified capability gaps, and approved or denied operations based on deployment risk.
OFFENSIVE CYBER OPERATOR
OCT 2020 - JUN 2024
U.S. Air Force · Cyber Operations · San Antonio, TX
▾ Click to collapse
  • Conducted offensive cyber operations against defended foreign networks, executing initial access, privilege escalation, lateral movement, persistence, and collection.
  • As sole certified data handler, processed operational data from 30 cyber operations and produced threat intelligence reports that informed senior leadership decisions at the national level.
  • Coached 12 students to a 100% pass rate in an offensive cyber operator course, doubling the prior 55% average while supporting a $3.5M qualification program and finishing 10 days ahead of schedule.
  • Rebuilt a 109-module training range and launched an operational immersion program for 120 personnel, closing 14 critical gaps, raising assessment proficiency 47% and recovering 50,000+ hours of training value. Meritorious Unit Award.
ELECTRONICS & SYSTEMS TECHNICIAN
MAY 2017 - SEP 2020
U.S. Air Force · Ramstein Air Base, Germany
▾ Click to collapse
  • Performed component-level troubleshooting and root-cause analysis on complex electronics systems, authoring procedural change recommendations that were adopted as updated regional maintenance standards.
04
// BUILD LOG

PROJECTS

SocketCat
Live Solo Build

Open registry and metaregistry for MCP (Model Context Protocol) servers and portable multi-agent blueprints. Automated ingestion, permission-derived trust signals, and a full contribution layer. Designed, built, and shipped solo.

socketcat.com ↗
Next.js 15 React 19 TypeScript Cloudflare Workers OpenNext Neon Postgres Drizzle ORM Auth.js / OAuth GitHub Actions
Automated ingestion pipeline. A daily GitHub Actions job pages the official MCP registry plus npm, PyPI, Docker, and GitHub, derives each server's permissions from its declared secrets and remotes, enriches with live stars and download counts, and upserts into Postgres without ever overwriting human reviews. Over 23,000 servers indexed.
Portable blueprint format and compiler. Designed a framework-neutral schema that lowers to a control-flow IR, runs on a reference interpreter as the semantic oracle, and targets pluggable backends (LangGraph, CrewAI) behind a capability model. A conformance suite runs every case on every engine, so it compiles where a target supports the control flow and refuses loudly where it does not.
Shipped on an edge stack. Next.js on Cloudflare Workers via OpenNext, GitHub OAuth through Auth.js, Postgres full-text search, and a contribution layer (reviews, saves, publishing) namespaced to GitHub identity. Solved real edge-runtime issues around request-time secret access and CI secret persistence.
Trust as a first-class concern. Stripped fabricated trust signals and surface only permissions actually derived from server metadata. A server's works-rate stays hidden until it has earned real reviews.
GuildCyberLive

AI red team platform. Live, attackable AI targets with 15 graded challenges covering prompt injection and agentic tool abuse, mapped to the OWASP LLM Top 10 and MITRE ATLAS and graded on whether the attack lands. In front of the targets sits a two-stage prompt injection guard: a heuristic filter, then a logistic regression classifier over bge-small embeddings, with retraining gated on F1.

AI Red TeamPrompt InjectionOWASP / ATLAS
guildcyber.com ↗
Portfolio LLM AssistantRemediated

Red team and remediation of this site's own chat assistant. Found that the chat proxy accepted a client-supplied system prompt, an open model proxy on my API key that bypassed every guardrail at the trust boundary. Remediated by moving the prompt and policy server-side and adding rate limiting and input validation.

AI Red TeamTrust BoundaryCloudflare Workers
Sigma Detection Rule LibraryOpen Source

Detection rules mapped to MITRE ATT&CK, translating firsthand offensive tradecraft into behavioral detections for credential access, lateral movement, and persistence. Built with false-positive reduction as a primary design concern.

SigmaMITRE ATT&CKDetection
github.com/ocnu ↗
05
// CAPABILITY ASSESSMENT

SKILLS & TOOLS

01

AI Security

  • AI Red Teaming
  • LLM Security
  • Prompt Injection
  • Jailbreak Analysis
  • Adversarial ML
  • AI Model Evaluation
  • Model Behavior Evaluation
  • Agentic Security
  • MCP / Tool-Use Risk
  • OWASP LLM Top 10
  • MITRE ATLAS
  • AI-Assisted Detection
02

Offensive Security

  • Red Team
  • Adversary Emulation
  • Penetration Testing
  • Vulnerability Assessment
  • Exploit Development
  • Privilege Escalation
  • Lateral Movement
  • C2
  • AV Evasion
  • OSINT
03

Detection & Response

  • EDR
  • SIEM / Splunk
  • Sigma
  • MITRE ATT&CK (Ent + ICS)
  • Behavioral Detection
  • Threat Hunting
  • Threat Intelligence
  • Incident Response
  • Malware Analysis
  • Digital Forensics
  • Reverse Engineering
  • Volatility / Wireshark
04

Tooling

  • Cobalt Strike
  • Metasploit
  • BloodHound
  • Mimikatz
  • NetExec
  • Hashcat
  • Burp Suite
  • Nmap
  • Ghidra
  • Nessus
05

Platforms & Infrastructure

  • Windows / Linux / Kali
  • Active Directory
  • TCP/IP / DNS / HTTP/S
  • IDS / IPS
  • Zero Trust
  • AWS
  • Cloudflare Workers
  • Cloud Architecture
06

Scripting & Development

  • Python
  • scikit-learn
  • Bash / PowerShell
  • TypeScript
  • SQL
  • Next.js / React
  • Firebase
  • Postgres
07

Frameworks & Governance

  • NIST CSF / RMF
  • OWASP
  • Cyber Kill Chain
  • Threat Modeling
  • AI Governance
06
// CREDENTIALS · EDUCATION · AWARDS

CREDENTIALS

// Certifications
GIAC
GPEN
ACTIVE
GIAC
GCIH
ACTIVE
Military / IC
CNOQC
MILITARY
Military / IC
FORGE
MILITARY
CompTIA
Security+
ACTIVE
CompTIA
A+
ACTIVE
CompTIA
Project+
ACTIVE
AWS
Cloud Practitioner
ACTIVE
CompTIA
Network+
ACTIVE
CompTIA Stackable
IT Operations Specialist
ACTIVE
CompTIA Stackable
Secure Infrastructure Specialist
ACTIVE
// Education
B.S. Information Technology
Western Governors University
Includes CompTIA Network+, Security+, and AWS Cloud Practitioner.
A.A.S. Cyber Security
Community College of the Air Force
A.A.S. Microprecision Technology
Community College of the Air Force
// Awards & Recognition
Air and Space Achievement Medal · Personal decoration for meritorious service
Distinguished Graduate · Top of class, Airman Leadership School
Outstanding Unit Award · Cyber exercise performance
Airman of the Year · Group level; selected to represent group at wing competition
07
// INITIATE CONTACT

MAKE CONTACT

SkillBridge candidate, separating May 2027. Open to AI security research, red team, adversarial evaluation, detection engineering, and threat operations roles across government, defense, and private sector. Or just want to talk shop? Reach out.

OPERATOR AI
Ask me about Stephen Oh