Independent software assurance and security research focused on legacy systems, cryptographic integrity, forensic analysis, and reproducible technical evidence.
| Repository | Description |
|---|---|
| cobol-shield | Static analysis toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity |
| vtr-forensic-img | Hybrid Rust+Python forensic image analysis — binary parsing, chain of custody, adversarial test suite |
| cryptofault | Passive PCAP and certificate analysis for OT/ICS — TLS version detection, weak keys, plaintext sessions |
| cfg-shield | Feature flag semantic drift detector for Rust — confirmed against generic-ecies |
- FreeBSD — crp/mbuf/refcount leak fix in
sys/net/if_ovpn.c— rGa841961da752 — merged by kp (Kristof Provost) - RustCrypto/crypto-bigint — documentation clarification for
xgcd_vartimedelegation — PR #1333 - IBM/Bank-of-Z — copy-paste defect in ABND-TIME seconds field across 23 CICS programs — PR #210 open, linked to issue #205
- generic-ecies — SharedInfo1/2 analysis per SEC 1 v2.0 §5.1.3 — issue #2, PR in preparation
- Tailscale — FreeBSD pkg version mismatch root cause analysis —
tailscale updatereads binary version instead ofpkg queryoutput, causing repeated daemon restarts on port revisions — issue #18136
- Source Transformation Integrity in Legacy COBOL Systems — DOI 10.5281/zenodo.21973424 — Zenodo, 2026, CC BY 4.0
Each project distinguishes observed facts from inference and projection. Security claims require a reproducible artifact — hexdump -C, not visual render.