DFIR Work & AI Security Research

Incident response and digital forensics from professional engagements, and open research on the security of AI agents.

Selected investigations from my professional work in detection and response. All reports are anonymized to protect client confidentiality — names, hosts, and identifying details are altered or omitted; the tradecraft and methodology are real.

Alongside the case work above, I am building a body of open research on the security of AI agents — how well they perform real defensive-security tasks, how they fail, and how their activity can be investigated and detected. Write-ups and code will be published here as each piece lands.

Research · AI security · 2026Coming soon

AI Security — Evaluating and Investigating Autonomous Agents

A planned series of open, published work on AI agents in defensive security: an evaluation benchmark measuring how well agents handle genuine analyst tasks — triaging labeled alerts, reconstructing intrusion timelines, and classifying malicious PowerShell — across several models.