I built STAS, a malware-analysis platform that reconstructs behavioral timelines, extracts and enriches indicators of compromise, and automates YARA and Sigma rule generation. I also built ShadowForge to validate ATT&CK-aligned detections with realistic Windows and Linux telemetry.
At Wenawa, I replaced Prophet/ARIMA with a Quantile GBDT forecasting engine and added SHAP explainability for auditable risk analysis. I also introduced Casbin-based ABAC and migrated password hashing to Argon2id with backward compatibility.
As an independent security researcher and consultant, I’ve tested web, API, and infrastructure security for NDA clients and researched programs across HackerOne, Bugcrowd, and Intigriti. I responsibly disclosed an unauthenticated Mastercard/Maestro cardholder PII exposure through HackerOne.

