projects
Things I've built and things I'm building
Research from my MSc, side projects I chose myself, and lab work I publish as I go. Each has its own writeup with context, decisions, and what I'd do differently next time.
MSc thesis · 2026 shipped
SCFusion
A cross-layer detection framework that fuses build-time and eBPF runtime signals to catch software supply chain attacks that either layer alone would miss.
Side project · 2026 in progress
A deliberately vulnerable package registry
An npm-style package registry with attack scenarios baked in, so people learning supply chain security can practice detection against realistic targets.
Lab writeups · 2026 in progress
PortSwigger Web Security Academy
Working through the Web Security Academy with Burp Suite, publishing writeups of each track as I finish it.