______ _____ __ _ __ __
/ ____/___ __________ ____ ____ _ / ___// /_ ____ _(_) /__/ /_
/ /_ / __ `/ ___/ __ \/ __ \/ __ `/ \__ \/ __ \/ __ `/ / //_/ __ \
/ __/ / /_/ / / / /_/ / /_/ / /_/ / ___/ / / / / /_/ / / ,< / / / /
/_/ \__,_/_/ \____/\____/\__, / /____/_/ /_/\__,_/_/_/|_/_/ /_/
/_/
Security Researcher @ Dynatrace
Cloud Security · AI-Augmented Defense · Runtime Detection
I make security runtime-observable, automatically testable, and AI-augmented.
SHIPPED
Kimera — Cloud security posture management. Assess, exploit, remediate, enforce. Uses LLMs to generate remediations from live cluster state. Dynatrace OSS.
Kalm-Benchmark — 235+ intentionally vulnerable manifests benchmarking 12 security scanners. CCSS scoring and interactive analysis. Dynatrace OSS.
HARIS — Black-box web security scanner. Orchestrates five tools, cross-correlates findings, uses LLMs for triage and remediation planning.
Tetragon MCP — MCP server exposing runtime security events to AI assistants. Multi-cluster support, dual-transport.
harnessport — Universal converter between AI coding harness configs. Claude Code ↔ OpenCode ↔ Cursor ↔ Windsurf ↔ Copilot ↔ Codex CLI.
LinkVault — Obsidian plugin that uses AI to categorise web clips into structured knowledge bases.
WRITING
Container misconfigurations — from theory to exploitation · Oct 2025
Kubernetes misconfiguration attack paths and mitigation · Apr 2025
Understanding Kubernetes security misconfigurations · Apr 2025
Tracing Apache Struts CVE-2024-53677 · Feb 2025