I take security apart at the silicon level. Firmware extraction over SPI, JTAG, UART and SWD, reverse engineering of drone and IoT ecosystems, and now AI/ML and MCP protocol security. Credited with 2 CVEs, author of 5 publications, and builder of tools that turn research into practice.
Presenting poster research on forensically sound firmware acquisition from consumer drones, including a false-acquisition failure mode discovered on the Holy Stone HS360S where the readout silently returns invalid data.
A methodology for low-cost consumer drones, validated as a case study across three Holy Stone platforms. Covers SPI, JTAG, UART and SWD acquisition paths with integrity verification at each stage.
Threat modeling LLM agent ecosystems: MCP protocol attack surfaces, adversarial machine learning, and secret leakage detection in AI-assisted developer workflows.
Hardware-level analysis of medical IoT (EMAY pulse oximeter, SYD8810 BLE SoC) and consumer cameras (Wyze Cam OG), tracing data flows from sensor to cloud.
IEEE-format survey synthesizing 150+ sources on firmware extraction and vulnerability analysis techniques, building a taxonomy of acquisition methods across device classes.
Dissertation research spanning consumer drone firmware security, hardware acquisition methodology, and forensic readiness of low-cost UAV platforms. Expected graduation May 2027.
The drone exposes an unsecured Wi-Fi access network with no access control. Any user can connect, passively capture drone traffic disclosing the RTSP server address, and attach to the live video stream.
An undocumented telnet service runs on port 23 with default credentials. A remote attacker can authenticate to the service and is immediately granted root permissions on the flight controller.
Physical acquisition from flash chips and debug ports. Desoldering, in-circuit reads with SOIC8 clips and CH341A programmers, and validation methodologies that catch silent acquisition failures.
End-to-end assessments of consumer drones, medical IoT and smart home devices. Attack vector taxonomies, exploit chains, and TTP mapping to MITRE ATT&CK and OWASP frameworks.
Emerging focus on LLM agent threat models, MCP protocol attack surfaces, adversarial machine learning, and automated secret leakage detection in AI-assisted code review.
Memory and disk forensics, malware behavioral analysis, and forensically sound acquisition. 20+ malware samples documented with IOC extraction mapped to known TTPs.
Security scanning platform combining secret leakage detection, static analysis and LLM agent security rules to flag exposed credentials and insecure patterns in developer workflows. Built around Zero Trust and shift-left principles.
Full-stack threat intelligence platform aggregating 50+ drone and UAV vulnerabilities mapped to the OWASP Drone Top 10 and MITRE ATT&CK, with an automated CVE ingestion pipeline pulling real-time data from NVD.
Automated analysis tool that parses firmware binaries and network captures to detect 15+ sensor types, identify data exfiltration destinations, and generate privacy risk scores for IoT devices.
End-to-end vulnerability assessments on Holy Stone drones. Authored 9 security guidelines and a published attack vector taxonomy, reducing the potential breach surface by 45%. Foundation of both CVEs and the ICCWS paper.
Automated firmware analysis tool written in Go for security assessment of embedded systems and IoT devices: unpacking, string and secret hunting, and structure identification.
Locally hosted cybersecurity laboratory environment with challenge watermarking and integrity verification, used to train 100+ students. Published as a pedagogy study at INTED 2026.
Across security courses, CTF labs, and tutoring with 95% satisfaction
Two-person team in the National Cyber League graduate bracket
Memory forensics, crypto and network security challenges for FITSEC & Cyber Heroines
Algorithms, Big Data, Python, Formal Languages: grading, labs & instruction
Research collaboration, AI red teaming, firmware security, or speaking opportunities. Serious inquiries decoded at full baud rate.