Operating across both sides of the kill chain — Red Team adversary simulation
and Blue Team detection engineering — as a unified discipline.
Active Arch Linux user · CTF competitor · Cloud IAM researcher · LLM security practitioner.
Purple Team is not a compromise — it's the deliberate fusion of adversarial thinking with detection precision.
Thinking like an adversary. Mapping attack surfaces, abuse paths, and exploitable gaps before they become incidents.
Translating attacker behaviour into detection logic. Building systems that catch what most tools miss.
The loop between attack and detect — run continuously, not once.
Execute an adversary technique against a real environment — cloud, endpoint, or application layer.
Check whether the attack generated a log, triggered an alert, or passed through silently. Document the visibility gap.
Write detection logic — SIEM rules, queries, or ML models — that reliably catches the technique without excess noise.
Re-run the attack to confirm detection fires. Iterate on evasion variants until the rule is robust.
Research, builds, and ongoing efforts across the full purple team spectrum.
Actively identifying and responsibly disclosing vulnerabilities on HackerOne and Intigriti across web and cloud targets.
Building proof-of-concept detection pipelines that convert MITRE ATT&CK techniques into inspectable, testable SIEM rules.
Using large language models to summarize alerts, cluster anomalies, and surface high-confidence findings from noisy logs.
Enumerating misconfigured IAM policies, privilege escalation paths, and cross-account trust relationships in AWS & GCP environments.
Hypothesis-driven log hunting across CloudTrail, VPC Flow Logs, and endpoint telemetry for indicators of living-off-the-land attacks.
Probing LLM-based systems for prompt injection, data exfiltration, and jailbreaking — then designing guardrails that hold.
Ready to work together?
If you're running a security team and need someone who can attack, detect, and iterate — let's talk.