Frameworks, tools, and fieldwork.

Selected engineering work in fraud, security, and adversary knowledge. Explore the projects, their purpose, and the work behind them.

Projects catalog

11 projects

  1. Compare fraud and security frameworks, understand where their concepts correspond, and see where mappings or coverage are missing.

    Private source
    Crosswalks & graphsResearch
    More detailsHide details about FT3c

    About the project

    FT3c helps investigators and researchers compare fraud and security frameworks without losing the distinctions between them. Its crosswalk and graph catalog connects external concepts to FT3 and distinguishes reviewed mappings, proposals, gaps, and unassessed entries.

    The implemented work includes mapping validation, machine-readable graph and STIX exports, and coverage reports built against specific framework versions. I lead the project’s technical direction and mapping review.

    The crosswalk and export pipeline is implemented. Downstream MCP integration is planned; an available MCP service is not part of the current offering.

  2. A framework I created to describe fraud consistently. FT3 2.0 adds independent classifications and connects techniques to reusable detection and control knowledge.

    Mixed source
    FrameworkResearch
    More detailsHide details about FT3

    About the project

    FT3 gives fraud practitioners a shared way to describe behavior and connect that understanding to defensive work. I created the framework and continue to guide its evolution.

    FT3 1.0 has publicly available source. The 2.x generation adds independent classifications and connected detection/control records; the selected catalog release is 2.1.0, dated 13 September 2026. Access to 2.x is by request.

    Resources

  3. A threat investigation platform for querying, enriching, and visualizing complex relationships in a hypergraph, with AI-assisted investigation workflows.

    Source not disclosed
    Threat investigation
    More detailsHide details about ARC

    About the project

    A threat investigation platform for querying, enriching, and visualizing complex relationships in a hypergraph, with AI-assisted investigation workflows.

  4. Manage the lifecycle of Synapse Cortex power-ups, from authoring and validation to installation, environment promotion, and rollback.

    Private source
    Developer tooling
    TypeScriptPythonJavaScript+1 in details
    More detailsHide details about ARC package management

    About the project

    Manage the lifecycle of Synapse Cortex power-ups, from authoring and validation to installation, environment promotion, and rollback.

    The repository contains a CLI and library, deterministic build and verification tooling, a Git-backed registry model, desired-state tracking, and advisory diagnosis. The draft authoring pipeline is library-driven. Runtime behavior and production deployment were not tested as part of this read-only review.

    Languages & technologies

    • TypeScript
    • Python
    • JavaScript
    • Shell
  5. A research engine supporting FT3 by identifying candidate fraud techniques, extracting grounded behavior observations, and comparing them with existing taxonomy coverage.

    Source not disclosed
    Research tooling
    More detailsHide details about Acheron

    About the project

    A research engine supporting FT3 by identifying candidate fraud techniques, extracting grounded behavior observations, and comparing them with existing taxonomy coverage.

  6. An instructor-led workshop on building threat intelligence workflows with Claude Code and the Team Cymru Scout API and MCP.

    Source not disclosed
    Workshop
    More detailsHide details about Threat intelligence workflow workshop

    About the project

    An instructor-led workshop on building threat intelligence workflows with Claude Code and the Team Cymru Scout API and MCP.

  7. STIG compliance automation organized around scripts for individual findings across multiple compliance frameworks.

    Public source
    Compliance tooling
    More detailsHide details about Aqueduct

    About the project

    STIG compliance automation organized around scripts for individual findings across multiple compliance frameworks.

  8. A coordinated set of AI-assisted workflows for researching, drafting, reviewing, and preparing editorial content and graphics.

    Private source
    Editorial tooling
    Python
    More detailsHide details about Editorial agent workflows

    About the project

    The project organizes editorial work into specialist roles for research, article structure, writing, voice review, graphics, and CMS preparation. It provides repeatable handoffs between those roles and keeps publication under human control.

    Authored bot profiles and skills are accompanied by scripts for packaging content, validating figure manifests, checking approvals, and assessing publication readiness. This is a workflow and tooling project; the repository does not establish a fully operational automated publishing service.

    Languages & technologies

    • Python

    Current state

    Workflow tooling implemented; production publication readiness remains on hold in the inspected documentation.

  9. Structured tools for collecting field notes and turning trip material into consistent, outcome-focused reports.

    Private source
    Reporting tooling
    PythonShell
    More detailsHide details about Field reporting toolkit

    About the project

    The toolkit organizes trip material into structured records that can be validated and assembled for review and delivery. Separate collection and reporting roles help preserve the distinction between observations and the report built from them.

    The inspected source contains record schemas, append and validation scripts, trip setup tooling, and an export-sealing workflow. Live operational use and reporting outcomes have not been verified in this website review.

    Languages & technologies

    • Python
    • Shell

    Current state

    Schemas and workflow scripts implemented; operational outcomes not verified.

  10. An investigation toolkit for organizing public-source collection, verification, and case reporting across specialist agent roles.

    Private source
    Investigation tooling
    PythonShell
    More detailsHide details about OSINT desk toolkit

    About the project

    The toolkit gives an investigation a structured case record and separates coordination, collection, resolution, verification, and monitoring responsibilities. Playbooks describe investigative methods while role-specific workflows govern how case material is handled.

    The repository includes case setup, validation and export tooling, passive collection adapters, capability probes, and automated test sources. Its capability inventory distinguishes implemented adapters from services that still require connection or validation; the available source does not prove that every integration is live.

    Languages & technologies

    • Python
    • Shell

    Current state

    Case tooling and passive adapters implemented; live integration readiness remains unverified.

  11. A planned evidence-compilation system for turning source reports into reviewed, traceable case files about adversary behavior.

    Private source
    Research tooling
    More detailsHide details about Adversary Behavior Dossiers

    About the project

    Adversary Behavior Dossiers is designed to preserve links between reported behavior, supporting evidence, and framework classifications. The proposed public case files would expose the evidence and analytical distinctions needed to assess their claims.

    The current repository is a documentation baseline covering the product, architecture, implementation plan, and release boundaries. The private compiler, public schemas and verifier, generated views, exports, and example dossiers are specified but not yet implemented. Planned FT3c integration would consume versioned releases rather than redefine the framework or author crosswalks.

    Current state

    Planned — documentation baseline; compiler and public outputs not implemented.

Working on a related problem?

Let’s compare notes