ASSURANCE ENGINEERING DETECTION APPSEC CLOUD OFFENSIVE AI SECURITY
↳ NEW HERE? START WITH TRUSTEDGE ⊕ REQUEST A TEARDOWN
I work on the load-bearing parts of security — how a control is evidenced, how risk becomes a number someone can act on, and how a system tells you it is being abused. I am mostly interested in why things fail and what makes them hold.
4,931 tests across the lab — AegisLens 108, TrustEdge 601, Pedigree 198, NullFire 424, BlackOut 230, AfterLife 290, sunset 44, credscope 93, sleeper 230, tombstone 497, parallax 191, throughline 150, ripple 523, NEXUS 170, interlock 553, touchstone 629. Counted from each repository's own README, not asserted here.
25 repositories across 7 of 7 domains. Open a domain, then open a repository — the second level is where the evidence is. Repository names link straight to the code.
ASSURANCE iso 27001 / isms / controls / evidence — 6 repositories
SecureBridge a whole ISMS, end to end
An interactive, evidence-driven ISO 27001 Integrated ISMS portfolio for SecureBridge Technologies Pvt. Ltd., connecting governance, risk, controls, policies, audits, evidence, management review, and certification readiness across 10 interconnected GRC projects.
| Read first | The risk register and the control-to-evidence mapping. |
AegisLens evidence in, risk scored, report out
AegisLens is an educational and defensive security assessment workbench using synthetic data. It is not a replacement for a SIEM, GRC platform, vulnerability scanner, or professional security audit.
| Stack | TypeScript Python CSS |
| Evidence | 108 tests, CI |
| Read first | backend/tests — if you want to know whether I can actually build. |
| Also in | ENGINEERING |
sunset what breaks when the cryptography expires
Cryptographic posture and post-quantum migration triage. Turns a CycloneDX CBOM into a deadline-anchored, risk-ranked migration plan — and says plainly what it could not assess. Offline, deterministic, no network.
| Stack | TypeScript CSS Python |
| Evidence | 44 tests, CI |
| Runs | Offline and deterministic. No network. |
| Read first | The triage output - especially the section listing what it could not assess. |
tombstone when retention and erasure collide
Retention x erasure reconciliation for security telemetry. Finds where security retention floors and privacy erasure obligations collide field by field, decides whether deletion is technically achievable, and emits machine-readable deletion metadata. Offline, deterministic, no dependencies beyond React.
| Stack | TypeScript HTML JavaScript |
| Evidence | 497 tests, CI |
| Read first | A field where the retention floor and the erasure obligation cannot both be met. |
| Also in | DETECTION |
parallax numbers that cannot carry the decision
Risk register measurement auditor. Finds where a qualitative risk register's numbers cannot support the decisions built on them, and triages the few risks worth quantifying.
| Stack | TypeScript JavaScript CSS |
| Evidence | 191 tests |
| Read first | The triage — which few risks are actually worth quantifying. |
NEXUS
EU Cyber Resilience Act Article 14 reportability and Clock of Record: evidence-backed reporting decisions, five separate timestamps, and a hash-chained audit ledger. Decision support, not legal advice.
| Stack | TypeScript JavaScript CSS |
| Evidence | 170 tests |
What I am chasing here: the smallest honest evidence set that proves a control operates.
ENGINEERING tooling / automation / pipelines — 4 repositories
AegisLens evidence in, risk scored, report out
AegisLens is an educational and defensive security assessment workbench using synthetic data. It is not a replacement for a SIEM, GRC platform, vulnerability scanner, or professional security audit.
| Stack | TypeScript Python CSS |
| Evidence | 108 tests, CI |
| Read first | backend/tests — if you want to know whether I can actually build. |
| Also in | ASSURANCE |
TrustEdge who outside your AWS account can get inside it
Grades who outside an AWS account can become an identity inside it, ranked by exposure x blast radius. Offline IAM trust-policy analyzer - no credentials, no API calls, zero dependencies.
| Stack | Python Dockerfile |
| Evidence | 601 tests, CI |
| Runs | Offline. No credentials, no API calls, nothing leaves the machine. |
| Read first | The trust-policy grading logic — that is where the argument is. |
| Also in | CLOUD |
Pedigree where did this dependency actually come from
Consumer-side npm provenance verification and policy enforcement. Verifies each dependency's origin against an expected source, then tells you what would break if you enforced it today. Verifies origin - not the absence of malicious code.
| Stack | TypeScript JavaScript |
| Evidence | 198 tests, CI |
| Read first | The dry-run report — what would break if you enforced the policy today. |
| Also in | APPSEC |
COLDSTART
Recovery-plan feasibility checker: models disaster recovery as a dependency graph and proves whether a valid recovery order exists from the state the disaster leaves behind.
| Stack | TypeScript JavaScript CSS |
Security work only counts once it runs unattended. This row is the difference between an opinion and a tool.
DETECTION telemetry / signals / triage — 7 repositories
PingMaster ping, with a graph
Ping, but with a graph. A simple, cross-platform tool for visualizing network latency. 🚀 A lightweight, intuitive, and cross-platform graphical ping for developers and network administrators.
| Stack | Rust Roff Dockerfile |
NullFire the Sigma rules that can never fire
Detection Matchability Analyzer - finds the Sigma rules that can never match your real post-pipeline data, explains why, and generates the minimal event that would prove each one can fire.
| Stack | Python |
| Evidence | 424 tests, CI |
| Read first | The matchability analysis — why a rule is dead against your real data. |
BlackOut one control failure, followed all the way through
Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.
| Stack | Python CSS JavaScript |
| Evidence | 230 tests, CI |
| Read first | The exploit, then the detection rule written against it. |
| Also in | APPSEC · OFFENSIVE |
AfterLife the password reset worked; the attacker stayed
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.
| Stack | Python JavaScript CSS |
| Evidence | 290 tests, CI |
| Read first | The naive detection rule that misses it - that contrast is the point. |
| Also in | APPSEC · OFFENSIVE |
tombstone when retention and erasure collide
Retention x erasure reconciliation for security telemetry. Finds where security retention floors and privacy erasure obligations collide field by field, decides whether deletion is technically achievable, and emits machine-readable deletion metadata. Offline, deterministic, no dependencies beyond React.
| Stack | TypeScript HTML JavaScript |
| Evidence | 497 tests, CI |
| Read first | A field where the retention floor and the erasure obligation cannot both be met. |
| Also in | ASSURANCE |
throughline
Can your telemetry actually connect the dots? An offline incident-response correlation-readiness analyzer: reads log-source schemas and reports which investigative pivots are possible, which break, exactly where, and which are genuinely undetermined.
| Stack | TypeScript JavaScript CSS |
| Evidence | 150 tests, CI |
TOURNIQUET
Remediation sequencing planner that models forensic evidence loss before destructive security changes.
| Stack | TypeScript CSS JavaScript |
A control you cannot observe failing is a control you are trusting on faith.
APPSEC secure sdlc / code review / supply chain — 8 repositories
Pedigree where did this dependency actually come from
Consumer-side npm provenance verification and policy enforcement. Verifies each dependency's origin against an expected source, then tells you what would break if you enforced it today. Verifies origin - not the absence of malicious code.
| Stack | TypeScript JavaScript |
| Evidence | 198 tests, CI |
| Read first | The dry-run report — what would break if you enforced the policy today. |
| Also in | ENGINEERING |
BlackOut one control failure, followed all the way through
Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.
| Stack | Python CSS JavaScript |
| Evidence | 230 tests, CI |
| Read first | The exploit, then the detection rule written against it. |
| Also in | DETECTION · OFFENSIVE |
AfterLife the password reset worked; the attacker stayed
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.
| Stack | Python JavaScript CSS |
| Evidence | 290 tests, CI |
| Read first | The naive detection rule that misses it - that contrast is the point. |
| Also in | DETECTION · OFFENSIVE |
Spectre seven services, thirteen ways in
Self-contained SSRF research lab — 7 services, 13 scenarios, 6 bypass techniques, detection rules, and an animated dashboard. All on 127.0.0.1.
| Stack | Python HTML PowerShell |
| Read first | The bypass techniques, then the detection rules written against them. |
| Also in | OFFENSIVE |
handler what a toolset can do in combination
Capability composition analysis for AI agent tool configurations. Finds what a toolset can do in combination, attributes each finding to exact tools, and computes the minimal change that breaks the path. Static, offline, deterministic.
| Stack | TypeScript CSS JavaScript |
| Evidence | CI |
| Read first | The minimal change that breaks the capability path. |
| Also in | AI SECURITY |
deadweight what happens when you load the model
AI model and skill supply-chain analyzer. Answers what happens when an AI artifact is loaded - without ever loading it.
| Stack | TypeScript JavaScript CSS |
| Evidence | CI |
| Read first | The pickle analysis — it answers the question without ever executing the artifact. |
| Also in | AI SECURITY |
ripple
Software supply-chain attack surface scanner: dependency confusion, typosquatting and package-risk signals. Read-only, offline by default.
| Stack | Python TypeScript JavaScript |
| Evidence | 523 tests |
interlock
INTERLOCK — PLC Safety Logic Integrity & Impact Analyzer. Turns PLC project changes (Rockwell L5X) into safety-impact evidence: symbolic scan, firing-condition analysis, AOI blast radius, alarm-path suppression, evidence-backed review set.
| Stack | TypeScript CSS JavaScript |
| Evidence | 553 tests |
Most of what breaks applications is authorisation and trust in things you did not write.
CLOUD identity / posture / logging / iac — 3 repositories
TrustEdge who outside your AWS account can get inside it
Grades who outside an AWS account can become an identity inside it, ranked by exposure x blast radius. Offline IAM trust-policy analyzer - no credentials, no API calls, zero dependencies.
| Stack | Python Dockerfile |
| Evidence | 601 tests, CI |
| Runs | Offline. No credentials, no API calls, nothing leaves the machine. |
| Read first | The trust-policy grading logic — that is where the argument is. |
| Also in | ENGINEERING |
credscope what the credential can actually do
Non-Human Identity attack surface assessment — know what the credential can actually do
| Stack | Python HTML |
| Evidence | 93 tests |
| Read first | The blast-radius scoring — a key is only as interesting as its reach. |
| Also in | OFFENSIVE |
sleeper the grant nobody revoked
OAuth grant drift & detectability review. Offline, deterministic, evidence-bounded — reach scored independently of detectability.
| Stack | TypeScript Python JavaScript |
| Evidence | 230 tests, CI |
| Runs | Offline and deterministic. |
| Read first | Where reach and detectability disagree — that gap is the finding. |
The gap between what a cloud provider promises, what a framework asks for, and what the policy actually permits.
OFFENSIVE attack paths / control validation — 6 repositories
BlackOut one control failure, followed all the way through
Security control failure & detection lab: an authorization fail-open, its exploit, root cause, fix, detection rule and regression test. Local red/blue lab, synthetic data only.
| Stack | Python CSS JavaScript |
| Evidence | 230 tests, CI |
| Read first | The exploit, then the detection rule written against it. |
| Also in | DETECTION · APPSEC |
AfterLife the password reset worked; the attacker stayed
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocation bug, its fix, a three-rule detection pack, and the naive rule that misses it.
| Stack | Python JavaScript CSS |
| Evidence | 290 tests, CI |
| Read first | The naive detection rule that misses it - that contrast is the point. |
| Also in | DETECTION · APPSEC |
Spectre seven services, thirteen ways in
Self-contained SSRF research lab — 7 services, 13 scenarios, 6 bypass techniques, detection rules, and an animated dashboard. All on 127.0.0.1.
| Stack | Python HTML PowerShell |
| Read first | The bypass techniques, then the detection rules written against them. |
| Also in | APPSEC |
credscope what the credential can actually do
Non-Human Identity attack surface assessment — know what the credential can actually do
| Stack | Python HTML |
| Evidence | 93 tests |
| Read first | The blast-radius scoring — a key is only as interesting as its reach. |
| Also in | CLOUD |
sigil
Offline ADCS ESC1-ESC17 Vulnerability Intelligence Platform — BloodHound CE analysis, no data leaves your machine
| Stack | TypeScript Python JavaScript |
touchstone
Independent evidence scorecard for CISA Secure by Design Pledge commitments: what public evidence can measure, what it cannot, and a reproducible run behind every number.
| Stack | TypeScript HTML JavaScript |
| Evidence | 629 tests |
Offence here exists to validate the defensive work above, not as a separate hobby.
AI SECURITY model supply chain / agent capability — 3 repositories
handler what a toolset can do in combination
Capability composition analysis for AI agent tool configurations. Finds what a toolset can do in combination, attributes each finding to exact tools, and computes the minimal change that breaks the path. Static, offline, deterministic.
| Stack | TypeScript CSS JavaScript |
| Evidence | CI |
| Read first | The minimal change that breaks the capability path. |
| Also in | APPSEC |
deadweight what happens when you load the model
AI model and skill supply-chain analyzer. Answers what happens when an AI artifact is loaded - without ever loading it.
| Stack | TypeScript JavaScript CSS |
| Evidence | CI |
| Read first | The pickle analysis — it answers the question without ever executing the artifact. |
| Also in | APPSEC |
regent
Reconstructs the authority chain behind AI-agent actions and verifies that delegated authority never silently expands. Deterministic delegation-chain verifier: attribution, authority monotonicity, action-time authorization.
| Stack | TypeScript CSS JavaScript |
| Evidence | CI |
The novel part is not the model. It is what loading an artifact, or composing a toolset, quietly grants.
HOW THE WORK FITS TOGETHER one diagram — click it to zoom
flowchart LR
G["GOVERN<br/><i>what must be true</i>"]
O["OBSERVE<br/><i>what is actually true</i>"]
B["BREAK<br/><i>how it fails</i>"]
D["DETECT<br/><i>would you notice</i>"]
V["VALUE<br/><i>what is it worth</i>"]
G -. "controls, deadlines, obligations" .-> O
O -. "findings" .-> V
B -. "a failure, and a rule for it" .-> D
D -. "coverage you can trust" .-> V
V -. "what to fix first" .-> G
The diagram is domain-level now rather than naming every repository — at sixteen that stopped being readable. The Index above is the navigation; every repository sits under the domain it belongs to, and the chart shows when each one landed.
The arrows are dashed for a reason. These are separate tools, not an integrated platform. The loop describes how the questions relate, not how the code does. Closing it for real is the interesting problem, and it is not done.
ON THE BENCH what the lab is doing right now — updated by Elis, not by me
Latest commits across every repository
467381atouchstone — fix: address CodeQL findings 4d agoc43d6d9touchstone — docs: add README with screenshots of the production build 4d ago0e1d234touchstone — docs: add methodology, architecture, threat model, data sources and poli 4d agob0ddc1ctouchstone — fix: describe the timeliness rules in the published formula text 4d ago0be2ccctouchstone — test: add end-to-end journeys and fix the accessibility issues they foun 4d ago
The queue. Anyone can add to it — the
REQUEST A TEARDOWN
link opens a prefilled issue, an Action sanitises the title, appends it here
and closes the issue. I work through it in roughly the order it arrives.
| In the queue | Requested by | Issue |
|---|---|---|
| S3 bucket policy evaluation order | @het-P301204 | #1 |
Think a repository is filed under the wrong domain? Say so — I would rather be corrected than flattering about my own work.
This is the workshop. The portfolio is where the story is.
hetpatel-lemon.vercel.app LINKEDIN EMAIL
The chart above rebuilds itself from the GitHub API every day. Every project uses synthetic data.