Skip to content
View het-P301204's full-sized avatar

Highlights

  • Pro

Block or report het-P301204

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
het-P301204/README.md

I work on the load-bearing parts of security — how a control is evidenced, how risk becomes a number someone can act on, and how a system tells you it is being abused. I am mostly interested in why things fail and what makes them hold.

4,931 tests across the lab — AegisLens 108, TrustEdge 601, Pedigree 198, NullFire 424, BlackOut 230, AfterLife 290, sunset 44, credscope 93, sleeper 230, tombstone 497, parallax 191, throughline 150, ripple 523, NEXUS 170, interlock 553, touchstone 629. Counted from each repository's own README, not asserted here.

Index

25 repositories across 7 of 7 domains. Open a domain, then open a repository — the second level is where the evidence is. Repository names link straight to the code.

ASSURANCE  iso 27001 / isms / controls / evidence  —  6 repositories
 SecureBridge  a whole ISMS, end to end

An interactive, evidence-driven ISO 27001 Integrated ISMS portfolio for SecureBridge Technologies Pvt. Ltd., connecting governance, risk, controls, policies, audits, evidence, management review, and certification readiness across 10 interconnected GRC projects.

Read first The risk register and the control-to-evidence mapping.
 AegisLens  evidence in, risk scored, report out

AegisLens is an educational and defensive security assessment workbench using synthetic data. It is not a replacement for a SIEM, GRC platform, vulnerability scanner, or professional security audit.

Stack TypeScript Python CSS
Evidence 108 tests, CI
Read first backend/tests — if you want to know whether I can actually build.
Also in ENGINEERING
 sunset  what breaks when the cryptography expires

Cryptographic posture and post-quantum migration triage. Turns a CycloneDX CBOM into a deadline-anchored, risk-ranked migration plan — and says plainly what it could not assess. Offline, deterministic, no network.

Stack TypeScript CSS Python
Evidence 44 tests, CI
Runs Offline and deterministic. No network.
Read first The triage output - especially the section listing what it could not assess.
 tombstone  when retention and erasure collide

Retention x erasure reconciliation for security telemetry. Finds where security retention floors and privacy erasure obligations collide field by field, decides whether deletion is technically achievable, and emits machine-readable deletion metadata. Offline, deterministic, no dependencies beyond React.

Stack TypeScript HTML JavaScript
Evidence 497 tests, CI
Read first A field where the retention floor and the erasure obligation cannot both be met.
Also in DETECTION
 parallax  numbers that cannot carry the decision

Risk register measurement auditor. Finds where a qualitative risk register's numbers cannot support the decisions built on them, and triages the few risks worth quantifying.

Stack TypeScript JavaScript CSS
Evidence 191 tests
Read first The triage — which few risks are actually worth quantifying.
 NEXUS

EU Cyber Resilience Act Article 14 reportability and Clock of Record: evidence-backed reporting decisions, five separate timestamps, and a hash-chained audit ledger. Decision support, not legal advice.

Stack TypeScript JavaScript CSS
Evidence 170 tests

What I am chasing here: the smallest honest evidence set that proves a control operates.

ENGINEERING  tooling / automation / pipelines  —  4 repositories
 AegisLens  evidence in, risk scored, report out

AegisLens is an educational and defensive security assessment workbench using synthetic data. It is not a replacement for a SIEM, GRC platform, vulnerability scanner, or professional security audit.

Stack TypeScript Python CSS
Evidence 108 tests, CI
Read first backend/tests — if you want to know whether I can actually build.
Also in ASSURANCE
 TrustEdge  who outside your AWS account can get inside it

Grades who outside an AWS account can become an identity inside it, ranked by exposure x blast radius. Offline IAM trust-policy analyzer - no credentials, no API calls, zero dependencies.

Stack Python Dockerfile
Evidence 601 tests, CI
Runs Offline. No credentials, no API calls, nothing leaves the machine.
Read first The trust-policy grading logic — that is where the argument is.
Also in CLOUD
 Pedigree  where did this dependency actually come from

Consumer-side npm provenance verification and policy enforcement. Verifies each dependency's origin against an expected source, then tells you what would break if you enforced it today. Verifies origin - not the absence of malicious code.

Stack TypeScript JavaScript
Evidence 198 tests, CI
Read first The dry-run report — what would break if you enforced the policy today.
Also in APPSEC
 COLDSTART

Recovery-plan feasibility checker: models disaster recovery as a dependency graph and proves whether a valid recovery order exists from the state the disaster leaves behind.

Stack TypeScript JavaScript CSS

Security work only counts once it runs unattended. This row is the difference between an opinion and a tool.

DETECTION  telemetry / signals / triage  —  7 repositories
 PingMaster  ping, with a graph

Ping, but with a graph. A simple, cross-platform tool for visualizing network latency. 🚀 A lightweight, intuitive, and cross-platform graphical ping for developers and network administrators.

Stack Rust Roff Dockerfile
 NullFire  the Sigma rules that can never fire

Detection Matchability Analyzer - finds the Sigma rules that can never match your real post-pipeline data, explains why, and generates the minimal event that would prove each one can fire.

Stack Python
Evidence 424 tests, CI
Read first The matchability analysis — why a rule is dead against your real data.
 BlackOut  one control failure, followed all the way through

Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.

Stack Python CSS JavaScript
Evidence 230 tests, CI
Read first The exploit, then the detection rule written against it.
Also in APPSEC · OFFENSIVE
 AfterLife  the password reset worked; the attacker stayed

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.

Stack Python JavaScript CSS
Evidence 290 tests, CI
Read first The naive detection rule that misses it - that contrast is the point.
Also in APPSEC · OFFENSIVE
 tombstone  when retention and erasure collide

Retention x erasure reconciliation for security telemetry. Finds where security retention floors and privacy erasure obligations collide field by field, decides whether deletion is technically achievable, and emits machine-readable deletion metadata. Offline, deterministic, no dependencies beyond React.

Stack TypeScript HTML JavaScript
Evidence 497 tests, CI
Read first A field where the retention floor and the erasure obligation cannot both be met.
Also in ASSURANCE
 throughline

Can your telemetry actually connect the dots? An offline incident-response correlation-readiness analyzer: reads log-source schemas and reports which investigative pivots are possible, which break, exactly where, and which are genuinely undetermined.

Stack TypeScript JavaScript CSS
Evidence 150 tests, CI
 TOURNIQUET

Remediation sequencing planner that models forensic evidence loss before destructive security changes.

Stack TypeScript CSS JavaScript

A control you cannot observe failing is a control you are trusting on faith.

APPSEC  secure sdlc / code review / supply chain  —  8 repositories
 Pedigree  where did this dependency actually come from

Consumer-side npm provenance verification and policy enforcement. Verifies each dependency's origin against an expected source, then tells you what would break if you enforced it today. Verifies origin - not the absence of malicious code.

Stack TypeScript JavaScript
Evidence 198 tests, CI
Read first The dry-run report — what would break if you enforced the policy today.
Also in ENGINEERING
 BlackOut  one control failure, followed all the way through

Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.

Stack Python CSS JavaScript
Evidence 230 tests, CI
Read first The exploit, then the detection rule written against it.
Also in DETECTION · OFFENSIVE
 AfterLife  the password reset worked; the attacker stayed

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.

Stack Python JavaScript CSS
Evidence 290 tests, CI
Read first The naive detection rule that misses it - that contrast is the point.
Also in DETECTION · OFFENSIVE
 Spectre  seven services, thirteen ways in

Self-contained SSRF research lab — 7 services, 13 scenarios, 6 bypass techniques, detection rules, and an animated dashboard. All on 127.0.0.1.

Stack Python HTML PowerShell
Read first The bypass techniques, then the detection rules written against them.
Also in OFFENSIVE
 handler  what a toolset can do in combination

Capability composition analysis for AI agent tool configurations. Finds what a toolset can do in combination, attributes each finding to exact tools, and computes the minimal change that breaks the path. Static, offline, deterministic.

Stack TypeScript CSS JavaScript
Evidence CI
Read first The minimal change that breaks the capability path.
Also in AI SECURITY
 deadweight  what happens when you load the model

AI model and skill supply-chain analyzer. Answers what happens when an AI artifact is loaded - without ever loading it.

Stack TypeScript JavaScript CSS
Evidence CI
Read first The pickle analysis — it answers the question without ever executing the artifact.
Also in AI SECURITY
 ripple

Software supply-chain attack surface scanner: dependency confusion, typosquatting and package-risk signals. Read-only, offline by default.

Stack Python TypeScript JavaScript
Evidence 523 tests
 interlock

INTERLOCK — PLC Safety Logic Integrity & Impact Analyzer. Turns PLC project changes (Rockwell L5X) into safety-impact evidence: symbolic scan, firing-condition analysis, AOI blast radius, alarm-path suppression, evidence-backed review set.

Stack TypeScript CSS JavaScript
Evidence 553 tests

Most of what breaks applications is authorisation and trust in things you did not write.

CLOUD  identity / posture / logging / iac  —  3 repositories
 TrustEdge  who outside your AWS account can get inside it

Grades who outside an AWS account can become an identity inside it, ranked by exposure x blast radius. Offline IAM trust-policy analyzer - no credentials, no API calls, zero dependencies.

Stack Python Dockerfile
Evidence 601 tests, CI
Runs Offline. No credentials, no API calls, nothing leaves the machine.
Read first The trust-policy grading logic — that is where the argument is.
Also in ENGINEERING
 credscope  what the credential can actually do

Non-Human Identity attack surface assessment — know what the credential can actually do

Stack Python HTML
Evidence 93 tests
Read first The blast-radius scoring — a key is only as interesting as its reach.
Also in OFFENSIVE
 sleeper  the grant nobody revoked

OAuth grant drift & detectability review. Offline, deterministic, evidence-bounded — reach scored independently of detectability.

Stack TypeScript Python JavaScript
Evidence 230 tests, CI
Runs Offline and deterministic.
Read first Where reach and detectability disagree — that gap is the finding.

The gap between what a cloud provider promises, what a framework asks for, and what the policy actually permits.

OFFENSIVE  attack paths / control validation  —  6 repositories
 BlackOut  one control failure, followed all the way through

Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.

Stack Python CSS JavaScript
Evidence 230 tests, CI
Read first The exploit, then the detection rule written against it.
Also in DETECTION · APPSEC
 AfterLife  the password reset worked; the attacker stayed

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.

Stack Python JavaScript CSS
Evidence 290 tests, CI
Read first The naive detection rule that misses it - that contrast is the point.
Also in DETECTION · APPSEC
 Spectre  seven services, thirteen ways in

Self-contained SSRF research lab — 7 services, 13 scenarios, 6 bypass techniques, detection rules, and an animated dashboard. All on 127.0.0.1.

Stack Python HTML PowerShell
Read first The bypass techniques, then the detection rules written against them.
Also in APPSEC
 credscope  what the credential can actually do

Non-Human Identity attack surface assessment — know what the credential can actually do

Stack Python HTML
Evidence 93 tests
Read first The blast-radius scoring — a key is only as interesting as its reach.
Also in CLOUD
 sigil

Offline ADCS ESC1-ESC17 Vulnerability Intelligence Platform — BloodHound CE analysis, no data leaves your machine

Stack TypeScript Python JavaScript
 touchstone

Independent evidence scorecard for CISA Secure by Design Pledge commitments: what public evidence can measure, what it cannot, and a reproducible run behind every number.

Stack TypeScript HTML JavaScript
Evidence 629 tests

Offence here exists to validate the defensive work above, not as a separate hobby.

AI SECURITY  model supply chain / agent capability  —  3 repositories
 handler  what a toolset can do in combination

Capability composition analysis for AI agent tool configurations. Finds what a toolset can do in combination, attributes each finding to exact tools, and computes the minimal change that breaks the path. Static, offline, deterministic.

Stack TypeScript CSS JavaScript
Evidence CI
Read first The minimal change that breaks the capability path.
Also in APPSEC
 deadweight  what happens when you load the model

AI model and skill supply-chain analyzer. Answers what happens when an AI artifact is loaded - without ever loading it.

Stack TypeScript JavaScript CSS
Evidence CI
Read first The pickle analysis — it answers the question without ever executing the artifact.
Also in APPSEC
 regent

Reconstructs the authority chain behind AI-agent actions and verifies that delegated authority never silently expands. Deterministic delegation-chain verifier: attribution, authority monotonicity, action-time authorization.

Stack TypeScript CSS JavaScript
Evidence CI

The novel part is not the model. It is what loading an artifact, or composing a toolset, quietly grants.

HOW THE WORK FITS TOGETHER  one diagram — click it to zoom
flowchart LR
  G["GOVERN<br/><i>what must be true</i>"]
  O["OBSERVE<br/><i>what is actually true</i>"]
  B["BREAK<br/><i>how it fails</i>"]
  D["DETECT<br/><i>would you notice</i>"]
  V["VALUE<br/><i>what is it worth</i>"]

  G -. "controls, deadlines, obligations" .-> O
  O -. "findings" .-> V
  B -. "a failure, and a rule for it" .-> D
  D -. "coverage you can trust" .-> V
  V -. "what to fix first" .-> G
Loading

The diagram is domain-level now rather than naming every repository — at sixteen that stopped being readable. The Index above is the navigation; every repository sits under the domain it belongs to, and the chart shows when each one landed.

The arrows are dashed for a reason. These are separate tools, not an integrated platform. The loop describes how the questions relate, not how the code does. Closing it for real is the interesting problem, and it is not done.

ON THE BENCH  what the lab is doing right now — updated by Elis, not by me

Latest commits across every repository

  • 467381a touchstone — fix: address CodeQL findings 4d ago
  • c43d6d9 touchstone — docs: add README with screenshots of the production build 4d ago
  • 0e1d234 touchstone — docs: add methodology, architecture, threat model, data sources and poli 4d ago
  • b0ddc1c touchstone — fix: describe the timeliness rules in the published formula text 4d ago
  • 0be2ccc touchstone — test: add end-to-end journeys and fix the accessibility issues they foun 4d ago

The queue. Anyone can add to it — the REQUEST A TEARDOWN link opens a prefilled issue, an Action sanitises the title, appends it here and closes the issue. I work through it in roughly the order it arrives.

In the queue Requested by Issue
S3 bucket policy evaluation order @het-P301204 #1

Think a repository is filed under the wrong domain? Say so — I would rather be corrected than flattering about my own work.

This is the workshop. The portfolio is where the story is.



hetpatel-lemon.vercel.app LINKEDIN EMAIL


The chart above rebuilds itself from the GitHub API every day. Every project uses synthetic data.

Popular repositories Loading

  1. PingMaster PingMaster Public

    Ping, but with a graph. A simple, cross-platform tool for visualizing network latency. 🚀 A lightweight, intuitive, and cross-platform graphical ping for developers and network administrators.

    Rust

  2. SecureBridge-ISMS-360 SecureBridge-ISMS-360 Public

    An interactive, evidence-driven ISO 27001 Integrated ISMS portfolio for SecureBridge Technologies Pvt. Ltd., connecting governance, risk, controls, policies, audits, evidence, management review, an…

  3. AegisLens-security-workbench AegisLens-security-workbench Public

    AegisLens is an educational and defensive security assessment workbench using synthetic data. It is not a replacement for a SIEM, GRC platform, vulnerability scanner, or professional security audit.

    TypeScript

  4. het-P301204 het-P301204 Public

    Profile README — a record of what I build.

    JavaScript

  5. TrustEdge-AWS-IAM-analyzer TrustEdge-AWS-IAM-analyzer Public

    Grades who outside an AWS account can become an identity inside it, ranked by exposure x blast radius. Offline IAM trust-policy analyzer - no credentials, no API calls, zero dependencies.

    Python

  6. Pedigree-npm-provenance-gate Pedigree-npm-provenance-gate Public

    Consumer-side npm provenance verification and policy enforcement. Verifies each dependency's origin against an expected source, then tells you what would break if you enforced it today. Verifies or…

    TypeScript