Primary work

ThreatWatch

liveopen source

What it does

ThreatWatch turns public cyber reporting into a living threat-state and decision ledger with stable records, visible uncertainty, and source-linked evidence.

My focus

Evidence gates, decision history, qualified hunt packages, and analyst-facing delivery that remains useful without an AI provider.

Threat IntelligenceDecision LedgerEvidence

RedBlue

liveprivate

What it does

RedBlue is a self-hosted external attack surface management platform for authorised discovery, bounded exposure checks, retained evidence, remediation tracking, and reporting.

My focus

Explicit authorisation, deterministic collection, safe scan boundaries, evidence lifecycle, and operations that remain useful without an AI provider.

EASMAuthorised ScopeEvidence Lifecycle