Skip to content
View calghar's full-sized avatar

Organizations

@dynatrace-oss

Block or report calghar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
calghar/README.md
    ______                                _____ __          _ __   __  
   / ____/___ __________  ____  ____ _   / ___// /_  ____ _(_) /__/ /_ 
  / /_  / __ `/ ___/ __ \/ __ \/ __ `/   \__ \/ __ \/ __ `/ / //_/ __ \
 / __/ / /_/ / /  / /_/ / /_/ / /_/ /   ___/ / / / / /_/ / / ,< / / / /
/_/    \__,_/_/   \____/\____/\__, /   /____/_/ /_/\__,_/_/_/|_/_/ /_/ 
                                /_/                                     

  Security Researcher @ Dynatrace
  Kubernetes Security · Offensive Testing · Detection Engineering

LinkedIn Scholar Blog Dynatrace OSS


SHIPPED

AI-driven offensive security

FORGE — Five-agent pipeline that builds a vulnerable app from CVE metadata, exploits it in a sandbox, and writes Sigma and Snort rules from the resulting traces. Dynatrace OSS · ARES 2026.

HARIS — Black-box web security scanner. Orchestrates five tools, cross-correlates findings, uses LLMs for triage and remediation planning.

Kubernetes & runtime security

VulnCare — Purposefully misconfigured multi-service K8s healthcare cluster for benchmarking automated remediation. 36 deployments, 4 namespaces, 31 injectable findings across 7 dependency classes, 5 validated exploit chains. Dynatrace Research · ESORICS 2026.

Kimera — K8s misconfiguration exploitation toolkit. Exposes ATT&CK techniques as MCP tools so agents can plan and run multi-step attack chains against live clusters. CLI and MCP server. Dynatrace OSS.

Kalm-Benchmark — 235+ intentionally vulnerable manifests benchmarking 12 security scanners. CCSS scoring and interactive analysis. Dynatrace OSS.

Tetragon MCP — MCP server exposing runtime security events to AI assistants. Multi-cluster support, dual-transport.

Side projects

gh-account-switcher — Go CLI for switching between multiple GitHub accounts.

harnessport — Universal converter between AI coding harness configs. Claude Code ↔ OpenCode ↔ Cursor ↔ Windsurf ↔ Copilot ↔ Codex CLI.

LinkVault — Obsidian plugin that uses AI to categorise web clips into structured knowledge bases.


RESEARCH

FORGE: Multi-Agent Graduated Exploitation and Detection Engineering AgentCy Workshop @ ARES 2026 · 603 CVEs · 67.8% end-to-end L1+ exploitation at ~$1.50/CVE

Does Runtime Topology Context Improve LLM-Generated Kubernetes Security Patches? LLM4Sec Workshop @ ESORICS 2026 · 248 trials · topology-dependent patch correctness 11.1% → 78.0%

Earlier papers and 8 US patents → Scholar


WRITING

Container misconfigurations — from theory to exploitation · Oct 2025

Kubernetes misconfiguration attack paths and mitigation · Apr 2025

Understanding Kubernetes security misconfigurations · Apr 2025

Tracing Apache Struts CVE-2024-53677 · Feb 2025

all posts

Pinned Loading

  1. gh-account-switcher gh-account-switcher Public

    Tool for quickly switching between multiple GitHub accounts

    Go 7 3

  2. dynatrace-oss/forge dynatrace-oss/forge Public

    Automated vulnerability analysis framework

    Python 1

  3. dynatrace-oss/kimera dynatrace-oss/kimera Public

    K8s misconfiguration exploitation toolkit

    Python 4

  4. LinkVault LinkVault Public

    Obsidian plugin to save and AI-categorise links into a structured knowledge base. Supports Claude, Ollama, and OpenRouter.

    TypeScript

  5. tetragon-mcp tetragon-mcp Public

    MCP server implementation for Tetragon

    Go 2 1