______ _____ __ _ __ __
/ ____/___ __________ ____ ____ _ / ___// /_ ____ _(_) /__/ /_
/ /_ / __ `/ ___/ __ \/ __ \/ __ `/ \__ \/ __ \/ __ `/ / //_/ __ \
/ __/ / /_/ / / / /_/ / /_/ / /_/ / ___/ / / / / /_/ / / ,< / / / /
/_/ \__,_/_/ \____/\____/\__, / /____/_/ /_/\__,_/_/_/|_/_/ /_/
/_/
Security Researcher @ Dynatrace
Kubernetes Security · Offensive Testing · Detection Engineering
SHIPPED
AI-driven offensive security
FORGE — Five-agent pipeline that builds a vulnerable app from CVE metadata, exploits it in a sandbox, and writes Sigma and Snort rules from the resulting traces. Dynatrace OSS · ARES 2026.
HARIS — Black-box web security scanner. Orchestrates five tools, cross-correlates findings, uses LLMs for triage and remediation planning.
Kubernetes & runtime security
VulnCare — Purposefully misconfigured multi-service K8s healthcare cluster for benchmarking automated remediation. 36 deployments, 4 namespaces, 31 injectable findings across 7 dependency classes, 5 validated exploit chains. Dynatrace Research · ESORICS 2026.
Kimera — K8s misconfiguration exploitation toolkit. Exposes ATT&CK techniques as MCP tools so agents can plan and run multi-step attack chains against live clusters. CLI and MCP server. Dynatrace OSS.
Kalm-Benchmark — 235+ intentionally vulnerable manifests benchmarking 12 security scanners. CCSS scoring and interactive analysis. Dynatrace OSS.
Tetragon MCP — MCP server exposing runtime security events to AI assistants. Multi-cluster support, dual-transport.
Side projects
gh-account-switcher — Go CLI for switching between multiple GitHub accounts.
harnessport — Universal converter between AI coding harness configs. Claude Code ↔ OpenCode ↔ Cursor ↔ Windsurf ↔ Copilot ↔ Codex CLI.
LinkVault — Obsidian plugin that uses AI to categorise web clips into structured knowledge bases.
RESEARCH
FORGE: Multi-Agent Graduated Exploitation and Detection Engineering AgentCy Workshop @ ARES 2026 · 603 CVEs · 67.8% end-to-end L1+ exploitation at ~$1.50/CVE
Does Runtime Topology Context Improve LLM-Generated Kubernetes Security Patches? LLM4Sec Workshop @ ESORICS 2026 · 248 trials · topology-dependent patch correctness 11.1% → 78.0%
Earlier papers and 8 US patents → Scholar
WRITING
Container misconfigurations — from theory to exploitation · Oct 2025
Kubernetes misconfiguration attack paths and mitigation · Apr 2025
Understanding Kubernetes security misconfigurations · Apr 2025
Tracing Apache Struts CVE-2024-53677 · Feb 2025



