DFIR Work & AI Security Research
Incident response and digital forensics from professional engagements, and open research on the security of AI agents.
/Case files
Selected investigations from my professional work in detection and response. All reports are anonymized to protect client confidentiality — names, hosts, and identifying details are altered or omitted; the tradecraft and methodology are real.
Fileless Malware Intrusion — From a Phishing Lure to a Remcos RAT
A single user opened a malicious link from a trusted business application, running a fileless JavaScript dropper that decoded a hidden PowerShell payload, concealed its next stage inside a PNG image, and loaded a Remcos remote-access trojan — traced end to end from the first MDR alert to the command-and-control channel.
Read the report →
Web Server Compromise — From a Public-Facing RCE to a Cobalt Strike Beacon
A public-facing IIS application was exploited through a known RCE (CVE-2019-6714), dropping a Cobalt Strike beacon that ran via DLL side-loading of a legitimate signed Java binary. The actor escalated to SYSTEM, built Windows-service and WMI persistence, and beaconed to a C2 domain masquerading as Microsoft Azure — contained by the EDR's managed threat-hunting team.
Read the report →
/AI security research
Alongside the case work above, I am building a body of open research on the security of AI agents — how well they perform real defensive-security tasks, how they fail, and how their activity can be investigated and detected. Write-ups and code will be published here as each piece lands.
AI Security — Evaluating and Investigating Autonomous Agents
A planned series of open, published work on AI agents in defensive security: an evaluation benchmark measuring how well agents handle genuine analyst tasks — triaging labeled alerts, reconstructing intrusion timelines, and classifying malicious PowerShell — across several models.