I specialize in penetration testing, vulnerability research, firmware and binary reverse engineering, Active Directory security, and embedded/IoT devices. My work spans enterprise environments, hardware, radio protocols, mobile applications, and custom embedded systems.
From a camera's flash chip to the trust relationships in Active Directory. Detailed writeups, source code, and talks behind the work.
IoT camera vulnerability research
Operation Big Brother
CVE-2023-41610
CVE-2023-41611
CVE-2023-41612
From an SPI flash dump to proprietary network protocols: firmware and binary analysis of the Victure PC420 uncovered a hardcoded root password, weak encryption, and code execution from micro-SD media. The work includes a Wireshark decoder and coordinated disclosure.
Exploring ADCS attack methods and defenses through talks and Damn-Vulnerable-ADCS, a PowerShell lab setup for testing NTLM relay vulnerabilities. Used in Iowa State University's Cyber Defense Competition.
Reverse engineering the recovery tool's decryption-ID checker with Ghidra: unpacking Nuitka output and tracing how SHA-256 hashes are compared against a lookup table.
Investigating garage-door radio protocols with accessible hardware. Research notes, a Python implementation for decoding Security+ 2.0 transmissions, and a practical walkthrough presented at SecDSM.
Also presented at Secure Iowa, BSides Iowa, and Iowa State University.
Beyond the engagement
Curiosity, with a soldering iron.
I enjoy taking systems apart: in software, with a debugger, and sometimes literally with a soldering iron. Outside professional penetration testing, I investigate embedded devices, unusual hardware, and security problems that have received little attention.
I also restore vintage computers and build security projects for competitions and the security community.