Security engineer and researcher turning low-level technical analysis into practical security outcomes: detections, investigations, response workflows, and tools.
My work spans systems security, reverse engineering, threat intelligence, incident response, detection engineering, and AI-enabled security automation.
- fkie-cad/cwe_checker — Former developer and maintainer of a cross-architecture binary-analysis tool that detects vulnerable patterns in compiled code.
- fkie-cad/FACT_core — Former developer and maintainer of a platform for automated firmware extraction, analysis, and comparison at scale.
- tbarabosch/pocs — Author and curator of proof-of-concept material for responsibly disclosed FreeBSD, NetBSD, OpenBSD, and VirtualBox issues.
- tbarabosch/apihash_to_yara — Author of a tool that generates YARA rules from Windows API hashes for malware detection and hunting.
- telekom-security/malware_analysis — Contributor of analysis scripts, YARA rules, and indicators published alongside threat research.
- facebookincubator/ForgeArmory — Contributor who added 17 commodity Linux TTPs to its MITRE ATT&CK-aligned catalogue for defensive validation.
- 15+ years across security research, engineering, threat intelligence, detection, and incident response.
- PhD in Computer Science on formalizing and detecting host-based code injection attacks in the context of malware.
- Systems security research: five disclosed CVEs and credit across 58 upstream BSD commits.
- Community service: Botconf programme committee member since 2017.
- Trap fuzzing: random instructions, real bugs — why random native instructions expose privileged failure paths.
- Detect API hashing with YARA — turning Windows API hashes into practical malware hunting rules.
- From Problem to Operations — an engineering workflow for security tooling that lasts.
- The Agentic Performance Ladder — one reverse-engineering workload across Python, native C++, and Metal.
Based on public repositories owned by this account; organization-owned contributions are not included.