Cybersecurity, AI & data science leader — 20+ years building production cyber-analytics platforms across enterprise, defense, and federal.

I build production-grade cyber data and analytics platforms — applying AI/ML, data science, and cloud engineering to defend networks and turn high-volume telemetry into decisions. Ph.D. in Computer Science, 20+ years across enterprise, defense, and federal environments.

Focus Areas

AI for Cyber

Offline/air-gapped LLM fine-tuning, MCP & agentic AI workflows, and ML-based anomaly detection on live network telemetry.

Network Defense & Forensics

Real-time situational awareness, threat detection at scale, and cyber-topology visualization for analysts and operators.

Data Science & Pipelines

Large-scale analytics pipelines, cloud data engineering on AWS/GCP, and ML modeling over messy, high-volume data.

Recent Posts

Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines

I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — some sessions are quick local edits, others are long-running debugging or evaluation runs I deliberately leave on a server. But opencode sessions are local by design. A session belongs to the machine and directory where it was born, and its useful context is split across two places: the saved conversation, and the working tree around it.

Read more →

MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)

Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world where the worst thing that happened to a packet was radio noise. MAVLink, the lingua franca of ArduPilot, PX4, and most commercial companion computers, ships by default with no authentication, no encryption, and no integrity protection beyond a CRC that exists to catch corrupted bytes rather than a deliberate forgery. Anyone who can reach the telemetry radio can ask the vehicle for its parameters. Anyone who can reach it can tell the vehicle to go somewhere else.

Read more →

Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench

A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the threat-intel workflows that would benefit most from an AI assistant are exactly the ones where pasting text into somebody else’s API is a no-go. Most LLM benchmarking quietly ignores this, because the benchmarks assume you can just call GPT. In my world you often can’t.

Read more →
Commodore 64 home computer
Sooner or later, someone has to shut-up and row. — Steve Henderson