projects
Real builds from the vault — security tooling, this site, and the work that is still in progress. Click a card for the write-up.
hippystyle.com
This site. Next.js 16, Sanity CMS, and a Y2K / Hackers-1995 rebuild now live on production.
● onlineSecurityrecon-ng
Modular open-source reconnaissance framework. Intel gathering, not exploitation — 109 modules wired up locally.
● onlineSecurityrecon-chain
recon-ng, httpx and nuclei chained into one pipeline: passive discovery, liveness probing, then a scoped active scan merged into one report.
● onlineSecuritysecurity-toolchain
Personal Bash toolchain for external attack-surface monitoring. Component 1, exposure-scan, is built.
◐ buildingSecuritydork-recon
Data-driven search-engine dork pipeline. Dorks live in a corpus file, not in the engine.
● onlineSecurityDC34 badge
Authorized firmware research on the DEF CON 34 Baochip-1x badge I own. Source-backed attack-surface map.
◐ buildingSecurity5n4ck3y CTF
AND!XOR's DEF CON 34 badge CTF. B.E.N.D.E.R world mapped; several puzzles still open post-con.
◐ buildingSecuritywatermarks-remover
Third-party tool for inspecting AI provenance marks — Unicode, statistical watermarks, and C2PA metadata.
◐ buildingCareerjob-search
Semi-automated SOC / security-analyst search: tailored packets in the vault, submit always human-gated.
◐ buildingSecurityblackbird
Username and email reverse-search across the WhatsMyName corpus. Existence checks, not profile scrapes.
● onlineSecurityholehe
Email-only account-existence checks across ~120 sites via login, register, and recovery probes.
● onlineSecurityghunt
Google-account profiling from an email: Gaia ID, public photos, services, Maps, and Calendar signals.
● online