Independent Security Researcher & Builder β Privacy-first defensive tooling for Linux.
VIGIL β eBPF-native EDR (v0.8.0) π΅
Endpoint Detection and Response with detection logic living in the kernel. Cross-view integrity (kernel vs /proc), temporal anomaly detection, self-integrity β built to resist the EvilEDR attack class. v0.8 adds multi-host fleet mode, alert routing (webhook/Slack/Discord/Telegram/email), and ARM64 support. Ships with a rootkit simulator so every claim is reproducible.
RingWatch β Real-time Ring -3 Monitor π£
Live Intel ME/CSME activity monitoring β HECI bus probing, firmware registers, MEI client tracking, and PMT telemetry, correlated with sysfs, dmesg, lsof, and network state. Read-only, zero risk: no system modifications. A 19-section dashboard with live charts for power consumption, MEI memory, and timestorm detection. One of the few public Ring-3 monitors in existence.
PITBULL β Autonomous Digital Explorer π± π
Autonomous Benevolent Yielding & Forensic Intelligence System β a digital explorer with personality, reasoning, and self-evolution that maps hidden, forgotten, and invisible corners of the internet. Honeypots and deception layers, Suricata IDS integration, a Neo4j-backed knowledge graph for memory, local-LLM reasoning (Ollama), a Cytoscape.js threat map, and a RAM Zero memory-hygiene module.
- eBPF-based kernel detection & integrity
- Intel ME / firmware-level security (Ring -3)
- Anti-rootkit techniques (cross-view, temporal, lineage)
- Privacy-first architecture: E2E encryption, minimal attack surface
- DoseStream β a medication reminder app with family circles, E2E-encrypted sync, and no data harvesting (launching soon)
MIT for userspace β’ GPL v2 for kernel eBPF (as the kernel demands)


