projects

10+
security tools
3
products shipped
2
domains: offense & markets
goblin
whatFast subdomain enumeration across passive sources and permutation engines.
whyRecon lives or dies on coverage; existing tools traded speed for depth.
howGo, concurrent source adapters, resolver pools from rexolvers.
nullscope
whatDiscover every domain an organization owns via RDAP + CT log pivoting.
whyScope discovery is the highest-leverage step of any engagement.
howRegistration-data graph walks cross-referenced with certificate SANs.
certsight
whatCertificate recon CLI — intelligence extraction from X.509 via CT logs.
whyCertificates leak infrastructure topology nobody meant to publish.
howStreaming CT ingestion, structured SAN/issuer/temporal analysis.
ctlogger
whatMonitor and record Certificate Transparency logs in real time.
whyNew certificates are an early signal of new infrastructure and phishing.
howLong-running CT log follower writing structured records.
cloudsurfer
whatCloud asset reconnaissance — surface exposed cloud resources.
whyCloud sprawl is where modern attack surface actually hides.
howGo, multi-provider enumeration and correlation.
rexolvers
whatFetch fresh, working DNS resolver lists from multiple sources.
whyEvery recon pipeline needs reliable resolvers; stale lists waste runs.
howAggregates and validates public resolver sources.
algotrix
whatNSE algo-trading platform: tick recorder, OHLCV pipeline, LLM consensus signals.
whyMarkets are an adversarial system too — same instincts, different target.
howGo feeds + TimescaleDB + a multi-agent quant scanner. (private)
pharmax
whatMulti-tenant eQMS SaaS for regulated Indian SMEs — audit-ready compliance workflows.
whyCompliance software for SMEs is stuck in the spreadsheet era.
howModern multi-tenant stack with industry templates and mobile-friendly UX.

…and dozens more experiments on github.