5h4d0wn1k/photo-organizer
Local-first, private-by-default photo & video library. Rust daemon + Flutter desktop with Android pairing; SQLCipher encryption, ChaCha20-Poly1305 vault, OCR & scene search, P2P LAN sync — all on-device.
Building something that whole human timeline remembers.
Local-first, private-by-default photo & video library. Rust daemon + Flutter desktop with Android pairing; SQLCipher encryption, ChaCha20-Poly1305 vault, OCR & scene search, P2P LAN sync — all on-device.
RAG retrieval-time poisoning detector — demand-recency discrimination, canary injection, provenance attestation; fully offline, SARIF+MD reports
Tech lead & founder building 198+ open-source security tools, offensive/defensive tooling, and secure full-stack systems. Student of AI/LLM security and wireless hardware.
Protocol Buffers - Google's data interchange format
Crypto attacks + credential cracking - hash identify/crack with rules, RSA/AES/DH attacks, cipher auto-decode, XTS-CPA.
Wireless defense & monitoring suite - WIDS sensor, deauth/evil-twin/rogue-AP detection, beacon anomaly scan, WPA3 survey.
BLE tracker and sniffer - Bluetooth Low Energy advertising scanning and device fingerprinting.
Zigbee/Thread IEEE 802.15.4 packet sniffer for ESP32-C6 — frame capture, header decoding, device tracking, channel control and CSV export for IoT research.
AI task management platform — Next.js 13 (TypeScript) frontend, Go Fiber REST API, JWT auth, WebSocket real-time tasks, OpenAI assistant, PostgreSQL.
Zero-trust readiness & correlation engine - ZTA pillar scoring with evidence, multichannel correlation.
Special function implementations
MITM detection probes — ARP/DNS/HTTP anomalies that reveal interception on a network.
Detection-only (blue team) network intrusion detection system — rules engine for port-scan, brute-force, C2-beacon, and exfiltration detection with live capture, pcap replay, and deterministic offline simulation.
Linux kernel and system activity monitor for detection research: process/network/file/syscall collectors, MITRE-mapped anomaly flags, optional eBPF backends, offline self-test.
ML-powered SIEM lite - anomaly-detection correlation over normalized event streams.
Lab-only MITM and spoofing suite — ARP spoof, DNS spoof, HTTP credential capture, https-split, passive monitor, guaranteed restore, dry-run by default.
Deterministic mutation-based protocol fuzzer for embedded IoT protocols — MQTT, CoAP, HTTP, and binary frames — with crash tracking, dedup, and triage reports for authorized security testing.
Hacking toolkit collection - consolidated offensive utilities for labs and education.
Exploit-development ladder — build a locally compiled vulnerable ELF and walk stack-overflow exploitation: De Bruijn patterns, PTRACE crash tracing, offset discovery, ROP gadget scanning, and ret2win PoC proof.
CTF challenge kit - pwn/crypto/web/reversing challenge builders and solve helpers.
Honeypot stack - multi-service decoys with session capture and attacker-playbook replay.
ML malware classifier - feature-based sample classification with explainability reports.
Binary recon suite - strings, sections, packers and embedded artifacts for RE triage.
Wireless offensive framework - byte-exact 802.11/BLE frame crafting/parsing; offline-only, safety-gated.
Web exploitation framework - OWASP Top-10 attack engines, built-in localhost vulnerable targets, AI-guided scan queue.
Premium web development services — React 18 + TypeScript + Vite, Three.js 3D visuals, SEO groundwork, consultation-booking API.
CORS misconfiguration scanner - origin validation and preflight-response flaw detection.
SSTI scanner — Jinja2/Twig/Mako/ERB/FreeMarker/Velocity/Smarty fingerprinting, math-eval detection, RCE/file-read payloads and multi-target fuzzing.
XXE injection toolkit — entity expansion, blind-OOB exfiltration and parser hardening tests.
HTTP request-smuggling tester - CL.TE/TE.CL desync payload validation.