Compare fraud and security frameworks, understand where their concepts correspond, and see where mappings or coverage are missing.
Private sourceCrosswalk & graph catalog
FT3
A framework I created to describe fraud consistently. FT3 2.0 adds independent classifications and connects techniques to reusable detection and control knowledge.
Mixed sourceFramework · 1.0 public / 2.x by request
Compare fraud and security frameworks, understand where their concepts correspond, and see where mappings or coverage are missing.
Private source
Crosswalks & graphsResearch
More detailsHide details about FT3c
About the project
FT3c helps investigators and researchers compare fraud and security frameworks without losing the distinctions between them. Its crosswalk and graph catalog connects external concepts to FT3 and distinguishes reviewed mappings, proposals, gaps, and unassessed entries.
The implemented work includes mapping validation, machine-readable graph and STIX exports, and coverage reports built against specific framework versions. I lead the project’s technical direction and mapping review.
The crosswalk and export pipeline is implemented. Downstream MCP integration is planned; an available MCP service is not part of the current offering.
A framework I created to describe fraud consistently. FT3 2.0 adds independent classifications and connects techniques to reusable detection and control knowledge.
Mixed source
FrameworkResearch
More detailsHide details about FT3
About the project
FT3 gives fraud practitioners a shared way to describe behavior and connect that understanding to defensive work. I created the framework and continue to guide its evolution.
FT3 1.0 has publicly available source. The 2.x generation adds independent classifications and connected detection/control records; the selected catalog release is 2.1.0, dated 13 September 2026. Access to 2.x is by request.
A threat investigation platform for querying, enriching, and visualizing complex relationships in a hypergraph, with AI-assisted investigation workflows.
Source not disclosed
Threat investigation
More detailsHide details about ARC
About the project
A threat investigation platform for querying, enriching, and visualizing complex relationships in a hypergraph, with AI-assisted investigation workflows.
Manage the lifecycle of Synapse Cortex power-ups, from authoring and validation to installation, environment promotion, and rollback.
Private source
Developer tooling
TypeScriptPythonJavaScript+1 in details
More detailsHide details about ARC package management
About the project
Manage the lifecycle of Synapse Cortex power-ups, from authoring and validation to installation, environment promotion, and rollback.
The repository contains a CLI and library, deterministic build and verification tooling, a Git-backed registry model, desired-state tracking, and advisory diagnosis. The draft authoring pipeline is library-driven. Runtime behavior and production deployment were not tested as part of this read-only review.
A research engine supporting FT3 by identifying candidate fraud techniques, extracting grounded behavior observations, and comparing them with existing taxonomy coverage.
Source not disclosed
Research tooling
More detailsHide details about Acheron
About the project
A research engine supporting FT3 by identifying candidate fraud techniques, extracting grounded behavior observations, and comparing them with existing taxonomy coverage.
A coordinated set of AI-assisted workflows for researching, drafting, reviewing, and preparing editorial content and graphics.
Private source
Editorial tooling
Python
More detailsHide details about Editorial agent workflows
About the project
The project organizes editorial work into specialist roles for research, article structure, writing, voice review, graphics, and CMS preparation. It provides repeatable handoffs between those roles and keeps publication under human control.
Authored bot profiles and skills are accompanied by scripts for packaging content, validating figure manifests, checking approvals, and assessing publication readiness. This is a workflow and tooling project; the repository does not establish a fully operational automated publishing service.
Languages & technologies
Python
Current state
Workflow tooling implemented; production publication readiness remains on hold in the inspected documentation.
Structured tools for collecting field notes and turning trip material into consistent, outcome-focused reports.
Private source
Reporting tooling
PythonShell
More detailsHide details about Field reporting toolkit
About the project
The toolkit organizes trip material into structured records that can be validated and assembled for review and delivery. Separate collection and reporting roles help preserve the distinction between observations and the report built from them.
The inspected source contains record schemas, append and validation scripts, trip setup tooling, and an export-sealing workflow. Live operational use and reporting outcomes have not been verified in this website review.
Languages & technologies
Python
Shell
Current state
Schemas and workflow scripts implemented; operational outcomes not verified.
An investigation toolkit for organizing public-source collection, verification, and case reporting across specialist agent roles.
Private source
Investigation tooling
PythonShell
More detailsHide details about OSINT desk toolkit
About the project
The toolkit gives an investigation a structured case record and separates coordination, collection, resolution, verification, and monitoring responsibilities. Playbooks describe investigative methods while role-specific workflows govern how case material is handled.
The repository includes case setup, validation and export tooling, passive collection adapters, capability probes, and automated test sources. Its capability inventory distinguishes implemented adapters from services that still require connection or validation; the available source does not prove that every integration is live.
Languages & technologies
Python
Shell
Current state
Case tooling and passive adapters implemented; live integration readiness remains unverified.
A planned evidence-compilation system for turning source reports into reviewed, traceable case files about adversary behavior.
Private source
Research tooling
More detailsHide details about Adversary Behavior Dossiers
About the project
Adversary Behavior Dossiers is designed to preserve links between reported behavior, supporting evidence, and framework classifications. The proposed public case files would expose the evidence and analytical distinctions needed to assess their claims.
The current repository is a documentation baseline covering the product, architecture, implementation plan, and release boundaries. The private compiler, public schemas and verifier, generated views, exports, and example dossiers are specified but not yet implemented. Planned FT3c integration would consume versioned releases rather than redefine the framework or author crosswalks.
Current state
Planned — documentation baseline; compiler and public outputs not implemented.