xenuki
A Rust tool that packs a Xen dom0's initramfs and Xen.cfg as additional PE sections into Xen.efi, so hypervisor and dom0 boot inputs validate as one signed binary under Secure Boot — one artifact, one trust boundary.
Bridge log — personal site
Information Security·Systems & Identity·Merchant Mariner
I'm an IT and information security professional with roots going back to Linux 2.0 — systems administration, DevOps, and infosec across regulated environments, Active Directory, AWS, IAM, Group Policy, and firewall hardening. I currently work rotations as a mariner, and study and build in concentrated bursts between watches. I'm rebuilding a shore-side career in systems administration and information security. My research interests are oriented toward red team and offensive security work, and DFIR, as well as UEFI and hypervisor security where a system's depth becomes an asset rather than a liability.
Hybrid identity, Group Policy, AWS IAM, and firewall hardening across regulated environments.
Analysis, malware triage, and writing up findings — including active work on a recent attack that has proven to be a rich case study due to the wide range of persistence vectors and EDR evasion that the attacker's malware utilized.
Trust-chain integrity, reverse proxy hardening, mTLS, and PKI. An example being the design and implementation of a secure vault architecture in AWS serving >700 secrets to all of my devices and machines.
Building a high quality skillset in red team methodologies — Security+ exam scheduled within a few weeks, OSCP/PNPT/eJPT on the roadmap.
A Rust tool that packs a Xen dom0's initramfs and Xen.cfg as additional PE sections into Xen.efi, so hypervisor and dom0 boot inputs validate as one signed binary under Secure Boot — one artifact, one trust boundary.
Consolidated years of scattered credentials — browser stores, KeePass databases, notes — into a self-hosted vault behind Docker, Postgres, and an nginx reverse proxy. Currently layering in mTLS with CA-issued client certs and DN-based authorization ahead of making it globally reachable, plus automated encrypted backups to S3.
Xen hypervisor with a hybrid Gentoo Linux dom0 and domU guests ranging from WS2025 providing AD <-> Entra Connect hybrid topology, Cloud Sync, and Azure Arc onboarding — the proving ground for both the AZ-104 study plan I created and the xenuki EUFI PE32+ binary packer project mentioned above.
Case notes and technique breakdowns — including those from a recent attack analyzed in Ghidra — covering API hashing, reflective loading, and C2 structure identification, write ups will be uploaded to this site when they are complete.