Private until they ship. Public drops land in Research.
| Project | What it is | Status |
|---|---|---|
| Lithium | Evidence-first monitoring dashboard and bot environment | internal |
| EQ | Multi-user evidence and policy platform | building |
| Threat Dashboard | Admin visibility dashboards over live telemetry | building |
| Messaging Platform | Self-hosted secure messaging stack | building |
| Area | What it gives you |
|---|---|
| Detections | KQL, Sigma, SPL, and signal logic. Deploy them. Tell me what's missing. |
| Automation | Validators, collectors, and helper scripts. PRs welcome. |
| Workbooks | SOC-style dashboard and visual analytics artifacts. |
| Research Notes | Malware research notes and public-safe writeups. |
| Releases | Versioned drops of stable lab content. |
Open to contribution. See CONTRIBUTING.md for the ground rules.
| Rule | |
|---|---|
| Evidence first | No claim ships without an artifact, log reference, or reproducible command. |
| Defensive and authorized | All work is scoped to authorized, public-safe security engineering. |
| No secrets | No credentials, private logs, or personal data in any project artifact. |
| Automation is accountable | Scripts explain what they read, what they changed, and what proves it worked. |
| Disagree? | Open a discussion. Evidence required. |
Every claim below links to a working artifact in the lab. No receipt, no row.
| Domain | Receipts |
|---|---|
| Detection Engineering | KQL · Sigma · SPL · YARA · CVE packs |
| SIEM & EDR Platforms | Microsoft Sentinel · Splunk app · Elastic · CrowdStrike · Cisco |
| Automation & Tooling | Python · C++ · Validators · GitHub Actions (this page builds itself) |
| Threat Research | Qilin ransomware · PromptFlux / FruitShell · White papers |
| SOC Operations | Playbooks & dashboards for AWS, Okta, Palo Alto, CrowdStrike, Snowflake, and five more platforms |
Built for receipts. The lab light stays on.




