Home / research

Security research.

Same notes as Writing — how each project was framed, then how it was built.

Building
2026.08

Building SafeSphere: React, FastAPI, and a clear risk decision

How v3 is structured — input → analysis → SAFE / SUSPICIOUS / DANGEROUS → next steps, with Postgres and Redis.

Root cause Detection Mitigation
Open research note →
Thinking
2026.07

Thinking SafeSphere: personal security for the rushed click

Why everyday people need SAFE / SUSPICIOUS / DANGEROUS — not a SOC dashboard — in the moment before they click.

Root cause Detection Mitigation
Open research note →
Building
2026.05

Building Sentinel: FastAPI, React, and live scan progress

How the toolkit was built — WebSocket progress, check suite, scoring engine, plain-English React report.

Root cause Detection Mitigation
Open research note →
Thinking
2026.04

Thinking Sentinel: scanners people can actually read

The product idea — paste a domain, get a transparent score and plain-English fixes, not a CVE dump.

Root cause Detection Mitigation
Open research note →
Building
2026.02

Building cybrotech.us: Next.js, copy, and a live threat map

How the site was shipped — page structure, brand voice, attack-vector animation, Vercel deploy.

Root cause Detection Mitigation
Open research note →
Thinking
2026.01

Thinking cybrotech.us: a company site that feels like the work

Sole designer/developer brief — brand voice, service clarity, and a threat map that earns its place on the homepage.

Root cause Detection Mitigation
Open research note →
Building
2025.10

Building the DLP platform: agent → events → policy → dashboard

How the system is structured — Windows agent, collectors, detection and policy engines, React over Node and PostgreSQL.

Root cause Detection Mitigation
Open research note →
Thinking
2025.09

Thinking DLP: visibility before the block button

Why the DLP platform started as architecture — insider leakage, USB, clipboard — and what I refused to fake.

Root cause Detection Mitigation
Open research note →
Building
2025.06

Building SilentStrike: Digispark HID lab with detections attached

How the lab was put together — payload fixtures, Windows observables, and mitigations next to every demo.

Root cause Detection Mitigation
Open research note →
Thinking
2025.06

Thinking SilentStrike: why a HID lab belongs on a blue-team desk

The idea before the Digispark — physical access still wins, and defenders need a safe way to see the chain.

Root cause Detection Mitigation
Open research note →