Skip to content
View texasbe2trill's full-sized avatar

Block or report texasbe2trill

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
texasbe2trill/README.md

I've spent 8+ years in security, most of it in detection and response: writing detections, hunting threats, running forensics, and serving as incident commander on high-impact incidents. I also build the security tools I want on hand during an investigation. The four security tools on this page are open source, tested, and green in CI, so you can read the code before you take my word for it.

35%

lower average time to mitigate
KQL over Sentinel and Defender

<3 min

time to acknowledge
for the response rotation

~42%

shorter median forensic case time
about 6h to 3.5h with Python automation

20

open-source Sigma rules
34 ATT&CK techniques and sub-techniques

🛡️ Spotlight: AlertSage

AI in the SOC, with a confidence gate. Paste a free-text incident into this open-source Python console and get a triage card back: incident class, severity, ATT&CK techniques, a playbook hint, and a case record. Its classifier is trained on 500,000 synthetic incidents, and it shows where an LLM helps triage and where it should stay out of the way. An analyst still moves every case from New to Closed.

AlertSage Bookmarks page with demo cases and the New, Triaging, Contained, Closed case status stepper

  • Classifier first. TF-IDF (5,000 features) plus 384-dimension sentence embeddings feed a logistic regression across 10 incident classes, from phishing and malware to insider threat and data exfiltration.
  • LLM when unsure, by default. In Fallback mode, the default, the LLM runs only when classifier confidence is low. Off never calls it, and Override sends every event to the LLM. In the demo, a 45%-confidence call took about 1.4 s in the classifier and about 5.8 s in the LLM, and came back as Phishing (ATT&CK T1566 and T1598).
  • Only known labels. The LLM can override the classifier only with schema-validated JSON and a known label, with synonyms normalized first. If it hedges, a forced second pass runs.
  • Your model, your keys. Anthropic, OpenAI, Hugging Face, or local llama.cpp, swappable per session, with a fallback when a key is missing.
  • Built for the analyst. Regex IOC extraction for 10 indicator types, VirusTotal enrichment with your own key, and one-click pivots to AbuseIPDB, Shodan, and GreyNoise.
  • Hunt and track. A hunt page with Lucene-style queries such as mitre:T1566 AND last:24h, case timelines with notes and tags, and CSV batch triage up to 500 rows.

Kill-chain view across 13 of 14 ATT&CK Enterprise tactics · 78 tests, CI green

Docs Live app View code
The live app sleeps when idle: click wake and give it a moment. The docs site is always up.


🚨 Incident Command

I have served as senior incident commander for high-impact security incidents and run every stage of the response:

Triage → Containment → Eradication → Recovery → Root cause

  • Malware, ransomware, and data protection incidents: recognized as incident commander for all three, and led ransomware eradication and recovery.
  • Briefings people can act on: delivered risk assessments and remediation guidance to engineers and leadership.
  • Identity-aware investigations: correlated endpoint, network, identity, and behavioral sources to rebuild multi-stage activity.
  • Threat hunting: led enterprise threat hunting and network forensic analysis, and built the Splunk dashboards and Python automation behind it.
  • For the next responder: wrote the investigation playbooks and response baselines they start from.
  • AI in my own casework: used LLMs in production to summarize unstructured case data, triage events, draft investigation notes, and pull IOCs, timestamps, and actor patterns out of free text.

🧰 More Security Tools

ScenarioKit storyboard listing matched Sigma rules and ATT&CK techniques macos-trust scan in baseline mode flagging an invalid code signature

Swift CLI · Sigma · Homebrew tap

Turns macOS Unified Log JSON into one offline HTML storyboard: a timeline with ATT&CK techniques attached. Its detections live as code: 20 Sigma rules for persistence, TCC, sudo, SSH, keychain access, process injection, and more, run by its own Sigma matcher.

20 Sigma rules · 34 ATT&CK techniques and sub-techniques · no network calls

Read the Sigma rules Code

Python CLI · SARIF 2.1.0 · Homebrew tap

A read-only posture and persistence audit for Macs: unsigned apps, Gatekeeper violations, LaunchAgents and LaunchDaemons, plus kernel and browser extensions. It audits entitlements for 24 sensitive permissions, and baseline mode shows only what changed since your saved baseline. SARIF output drops findings straight into GitHub code scanning.

59 tests · CodeQL and pip-audit on every push · no network calls or telemetry

Live report Code

policyforge sending a require_approval decision to the approval queue, a human approving it, then a drift check

Go · policy as code · CLI and REST API

Guardrails for AI agents and automation that act on production. A YAML policy answers allow, deny, or require_approval after 9 ordered checks. Bots, CI jobs, and AI agents get time-limited policy envelopes, so an expired session is denied. A require_approval decision goes to an approval queue, where a human can approve or reject it. Every decision lands in a SHA-256 hash-linked audit log, and drift detection re-checks past decisions against today's policy.

61 tests · 3 safety tiers · 4 policy packs · approval workflow

Code

205 tests across the four security tools, CI green on all four.


🛠️ Toolbox

Python, Go, Swift, Bash, Linux, Kubernetes, Git, GitHub Actions
Function At work, and in public code you can read
Detection as code Python detections in Panther, version controlled and peer reviewed, over high-scale fintech telemetry · public: 20 Sigma rules in ScenarioKit
SIEM and query Microsoft Sentinel, Splunk, Panther, KQL, SPL, and SQL. Made Snowflake monitoring queries about 20% faster for the on-call rotation.
Endpoint Microsoft Defender telemetry · public: macOS persistence and code-signing audit in macos-trust
Cloud and containers Daily CVE triage for Kubernetes containers and images; better SQL joins and filters saved about 2 hours per investigation · public: guardrails for bots and AI agents acting on infrastructure in policyforge
Hunting and forensics Enterprise threat hunting · network forensics · Splunk dashboards · Python artifact collection, log parsing, and enrichment · public: Lucene-style search over triaged cases in AlertSage
AI in the SOC LLMs in production for case summaries, IOC extraction, and event triage · public: confidence-gated LLM escalation in AlertSage
Reporting Findings turned into clear next steps for engineering and security leaders · public: SARIF 2.1.0 for GitHub code scanning, plus JSON and HTML reports, in macos-trust
Languages Python · Go · Swift · KQL · SPL · SQL · Monkey C

Work versus public code: the Panther, Sentinel, Defender, Splunk, Snowflake, and Kubernetes work above comes from my day jobs and isn't public. The repos on this page are the part you can inspect today. Also: two years managing an enterprise information security governance and risk program.


🧭 Beyond Security

Side projects built with the same habits: measure it, test it, ship it.

SolarHarvest pages on Garmin watches

Monkey C · Garmin Connect IQ · live on the Connect IQ Store

Connected-device engineering on tight hardware. One codebase runs on 17 Garmin device targets (22 solar watch models), 3 Connect IQ API generations, and 3 screen sizes. It fits the 128 KB data-field limit on the tightest devices. It measures battery drain and solar gain from the watch's own 1% battery steps and records 19 developer FIT fields to every activity.

112 unit tests across device tiers · 7 pages · no network calls

Get it on the Connect IQ Store Code

  • 📚 KoNotes: local-first reading analytics with local embeddings, clustering, and LLM chat, plus a 7-subcommand CLI. 645 tests.
  • 🏀 Hooplytics: NBA player models tested on later games they never saw (R² 0.615 for combined points, rebounds, and assists). A model is saved only if it passes an R² check. 30 tests.

📫 Let's Talk

Happy to compare notes on detection engineering, incident response, or putting LLMs to work in triage.

Email me Bluesky

Pinned Loading

  1. AlertSage AlertSage Public

    Open-source SOC console. Free-text security incident in, MITRE ATT&CK triage card out. TF-IDF + sentence-transformer classifier, multi-provider LLM dispatch, IOC enrichment, and case management.

    Jupyter Notebook 4 2

  2. macos-trust macos-trust Public

    Intelligent macOS security scanner that identifies unsigned apps, Gatekeeper violations, and suspicious persistence mechanisms with context-aware risk assessment. No false positive fatigue.

    Python 5

  3. policyforge policyforge Public

    A policy engine that decides, enforces, and proves every infrastructure action. Define roles, resources, and safety tiers in YAML — get allow/deny/require_approval decisions with a tamper-evident a…

    Go 2 1

  4. ScenarioKit ScenarioKit Public

    ScenarioKit is a Swift-based CLI tool for generating rich, offline security storyboards from macOS Unified Logs. Transform raw logs into beautiful HTML reports with automated rule matching (Sigma),…

    Swift

  5. SolarHarvest SolarHarvest Public

    A Connect IQ data field that finally tells you what your solar watch is actually doing with all that sunlight.

    Monkey C 4