Cybersecurity, AI & data science leader — 20+ years building production cyber-analytics platforms across enterprise, defense, and federal.
I build production-grade cyber data and analytics platforms — applying AI/ML, data science, and cloud
engineering to defend networks and turn high-volume telemetry into decisions. Ph.D. in Computer Science,
20+ years across enterprise, defense, and federal environments.
Projects
Experience
Ethos
Tutorials
AI for Cyber
Offline/air-gapped LLM fine-tuning, MCP & agentic AI workflows, and ML-based
anomaly detection on live network telemetry.
Network Defense & Forensics
Real-time situational awareness, threat detection at scale, and cyber-topology
visualization for analysts and operators.
Data Science & Pipelines
Large-scale analytics pipelines, cloud data engineering on AWS/GCP, and
ML modeling over messy, high-volume data.
Oct 9, 2026 · 62 min read
Dependency review is rightly built around security patches. Every upstream release also ships capabilities we could adopt. A Go 1.22 routing example shows how a small refactor can remove a dependency, and capscan, a Dependabot companion built on GitHub Agentic Workflows and running in a public demo repository, makes capability review a routine part of every update, and the same review runs out of band as an agent skill. It closes with lessons from building agents that read untrusted input.
supply-chaindependenciesgoaiagents
Read more →
Sep 30, 2026 · 16 min read
Part 2 adds a Wazuh SIEM on its own SOC VLAN, then reviews the whole build carefully, including a version pin meant to keep the agents in step with their manager that ended up upgrading all five past it.
cyberludusclaudecyber-rangeproxmox
Read more →
Sep 30, 2026 · 24 min read
Part 1 of a running log of building a cyber range by describing it to Claude Code connected to Ludus. Covers installing Ludus, deploying a segmented six-VM range from a paragraph of description, tapping its traffic passively, and generating realistic analyst activity for the tap to capture.
cyberludusclaudecyber-rangeproxmox
Read more →
Sep 21, 2026 · 6 min read
Introduces Breadcrumb, a small daemon-free tool that records where each opencode session lives, the git state of its workspace and a gist of the last prompt, so you can find and safely resume work across machines.
aiagentsopencodedeveloper-toolstypescript
Read more →
Sep 5, 2026 · 21 min read
Part 1 of a series on drone link security. Builds a simulated ArduPilot lab and the MAVIO workbench to measure what an unauthenticated MAVLink link exposes, from the parameter stream to commands that move the vehicle, and what that trust model means for the autonomy stacks, LLM-based ones included, that now sit on the other end.
cyberdronesmavlinkardupilotgazebo
Read more →