|
shipped projects live or installable |
Garmin watch models run SolarHarvest |
automated tests across my projects |
MITRE ATT&CK tactics mapped by AlertSage |
I'm a senior security engineer with 8+ years in the field, and I build the software around the security work: automation, detection logic kept in version control, and tools that ship with tests and live deployments. Outside of work I publish open-source projects, from a macOS security scanner and an LLM-assisted alert triage console to a Garmin watch app now live on the Connect IQ Store.
|
Detection · Forensics · IR CVE triage · KQL · detection-as-code |
Built · Tested · Deployed Python · Monkey C · CLIs · Streamlit |
4 pluggable LLM backends OpenAI · Anthropic · llama.cpp |
A data field for solar Garmin watches that measures what the sun is actually doing for your battery. Written in Monkey C, live on the Connect IQ Store, and built for watches that give a data field just 128 KB of memory.
- Measured, not marketed: battery drain and gain come from the watch's own 1% steps, and the solar benefit is fitted across activities with a fixed-effects regression.
- Built for tight hardware: fits that memory limit with room to spare, computes the sun's position on the watch, and makes no network calls.
- Shows up in Garmin Connect: 14 developer FIT fields, checked against real recorded activities.
22 watch models · 7 pages · 104 unit tests · 3 screen sizes
|
|
🛡️ AlertSagePython · scikit-learn · sentence-transformers · Streamlit · LLMs Free-text security incident in, MITRE ATT&CK triage card out. A fast classifier makes the first pass, then an LLM writes the rationale, with guardrails that fall back to deterministic output when the model drifts from the source text. 8-class taxonomy · 13 ATT&CK tactics · batch up to 500 rows |
Python · Typer CLI · SARIF 2.1.0 · Homebrew tap A read-only macOS security scanner for unsigned apps, Gatekeeper violations, and suspicious persistence, with vendor-aware risk scoring, entitlements auditing, and SARIF output for GitHub Advanced Security. 59 passing tests · baseline/diff mode · no network calls |
|
|
|
Python · scikit-learn · pandas · Streamlit NBA player outcome models built on 60+ leakage-safe features covering rolling form, matchup context, and rest, evaluated on a chronological split with an automated promotion gate. PRA R² 0.615 · 172K train / 43K test rows |
📚 KoNotesPython · Streamlit · LLMs · NLP A local-first reading tool that turns Kobo and Kindle highlights into searchable notes, with theme clustering, similarity search, LLM chat, and recommendations. 571 tests · 20+ modules · 7-subcommand CLI |
| Security | detection-as-code (Panther), forensic automation, KQL, Snowflake SQL, CVE triage, macOS trust assessment |
| Software | Python, Monkey C (Garmin Connect IQ), Typer CLIs, unit testing, memory- and CPU-constrained devices |
| Applied AI | LLM IOC extraction, incident classification, hallucination guardrails, multi-provider routing |
| Data & ML | scikit-learn, pandas, SQL, classification, regression, calibration, time-aware validation |
| Delivery | Streamlit dashboards, SARIF 2.1.0, JSON pipelines, REST APIs, Garmin FIT developer fields |
Currently exploring: on-device statistics for wearables, context-aware security scanning, and LLM grounding for structured extraction.









