Expose the blind spot
Find the external signals conventional monitoring misses.
Threat intelligence built for decisions that cannot wait. Deep- and dark-web research, digital-risk investigations, and AI-enabled systems reveal exposure earlier and turn scattered signals into action.
SEE EARLIER × DECIDE FASTER × BUILD LEVERAGE
Experience across financial services and frontline threat intelligence has shaped a practical view of risk: the most valuable signal is often outside the perimeter, incomplete, and already moving. The work connects deep- and dark-web activity, identity exposure, phishing infrastructure, ransomware, and third-party risk to the decisions leaders actually face.
That intelligence becomes more valuable when it scales. Analyst automation, open-source security tools, distributed Ray/K3s infrastructure, and local AI systems turn repeated manual work into durable capability. Results are tested in the lab, applied in real workflows, and shared in plain language.
Find the external signals conventional monitoring misses.
Separate evidence from assumptions, state confidence, and make the decision easier.
Automate repeatable work so skilled people stay focused on the problems that need them.
Frontline intelligence across a global cybersecurity leader and one of Canada’s largest financial institutions.
Investigates threats developing across the deep and dark web, digital-risk surfaces, identity exposure, and adversary infrastructure. Builds analyst automations that return hundreds of hours, strengthens repeatable workflows, and mentors new talent so intelligence scales beyond one analyst.
Built third-party breach policy, ran deep- and dark-web monitoring, investigated ransomware and phishing ecosystems, and supported compromised-data retrieval. Connected outside-the-perimeter risk to repeatable tracking and response across the bank.
VERIFIED CREDENTIALS
Hands-on offensive security, cloud AI, quantum computing, and a three-year cybersecurity education.
A simulated connectome, first-person vision, and a Minecraft reward system that taught me why a rising score does not mean a smarter agent.
Field note · LIGMA.BLOG ↗How public information could fuel AI impersonation agents, what the campaign evidence supports, and where familiar conversations need stronger verification.
Field note · LIGMA.BLOG ↗How quantization, CPU offloading, and stubborn optimism made a 320B-class model run on a single 16 GB consumer GPU.
A field-level look at redirect chains, geo-filtering, spoofed registration data, and fake sale pages—the infrastructure choices that help typosquatting campaigns hide in plain sight.
A direct map of eight failure modes, the controls that matter, and a practical path to securing enterprise AI.
OPEN-SOURCE BUILDS
When a workflow repeats, it becomes a tool.
Cuts the time between suspicious domain activity and analyst review.
Domain monitoring · Python↗ Cyber LLM RAGMakes security knowledge retrievable across a distributed local-AI stack.
Ray · K3s · Retrieval↗ Telegram Auto DownloaderTurns monitored channels into a repeatable collection pipeline.
Collection automation · Python↗ Fang / De-FangRemoves friction from safely sharing and restoring indicators.
Analyst utility · Web↗SELECT CONVERSATIONS
The strongest conversations start with an exposed asset, a weak signal, an intelligence process that will not scale, or a security decision missing evidence. If that sounds familiar, the channel is open.