Skip to content
View OpenSource-For-Freedom's full-sized avatar

Block or report OpenSource-For-Freedom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

typing tagline

LinkedIn Blue Team Threat Hunter CVE Research, Coordinated Disclosure profile views

// whoami

Marine, then gang investigator, now DevOps security. I work on CI/CD, supply chain and runtime detection, and I hunt CVEs in open-source packages.

// research

I hunt vulnerabilities and malicious code in the open-source supply chain, then get them fixed. My own pipeline watches npm, PyPI, RubyGems, crates.io, Packagist and Go as new releases ship. Each artifact is unpacked in a rootless, network-less container and never executed. Taint-tracking rules and dependency scanners run over it, and the results are deduplicated against OSV, GitHub Advisories, NVD and Red Hat. Every candidate is then validated by hand against the shipped code before it goes into a static CVE ledger. Most automated hits are noise; the job is proving which ones aren't.

  • CVE discovery & coordinated disclosure: command injection, credential exposure, SSRF, missing authentication, unsafe deserialization and sandbox escapes in libraries, SDKs and AI-agent tooling. Every finding goes to the maintainer privately, with affected versions, a suggested fix and a CVSS score, before anything is published.
  • Malicious code analysis: install-time payloads, obfuscated droppers, typosquats and suspicious package behaviour, caught before they reach a build.
  • Container & repository research: image layers, CI/CD workflows, leaked secrets and vulnerable dependencies across public repositories and registries.
  • Signature matching: YARA, Semgrep and IOC rules written, tuned against false positives, and shipped as detections.

Disclosure policy: private report first, 90 days or a fixed release (whichever comes first), then public. Published advisories will be listed here as they go live.

Threat Hunting Board of Truth

// T00ls

Rust Python .NET eBPF YARA SQLite GitHub Actions Linux Semgrep Trivy Podman OSV

@OpenSource-For-Freedom's activity is private