LogLens
C++20 Linux authentication evidence analysis with explicit parser uncertainty, multi-episode detections, and deterministic report contracts.
Systems-oriented work across Linux evidence, product-security workflows, and software supply-chain review. I build narrow, local-first tools that turn system, repository, and dependency evidence into deterministic artifacts, bounded findings, and reproducible review paths.
Building toward: monitoring, detection, and product-security engineering where defensive tools must be explainable, compatible with developer workflows, and reproducible by another engineer.
C++20 Linux authentication evidence analysis with explicit parser uncertainty, multi-episode detections, and deterministic report contracts.
Five local detection and investigation workflows with schema-validated artifacts, run manifests, digest provenance, and bounded AI assistance.
PyPI-published product-security guardrail with redacted output, baseline-backed scans, changed-file gates, and fail-closed configuration.
Release-facing SBOM and dependency review with JSON, Markdown, and SARIF artifacts plus conservative policy and provenance evidence.
Four Linux evidence mini-labs, including a versioned bridge from process and socket diffs to telemetry-lab-compatible JSONL.
A public-safe pattern library: 8 stable security patterns extracted from 10 source notes, with maturity and provenance enforced in CI.
Keep unsupported input visible instead of treating parser gaps as negative evidence.
Bound authentication clusters without turning repeated failures into a compromise verdict.
Distinguish username spread from ordinary repeated failure by one account.
Collapse duplicate alerts while preserving representative evidence and escalation signals.
Require a reproducible join key, event sequence, and time window before claiming a chain.
Review suppression drift as security-adjacent code rather than invisible maintenance.
Explain why a dependency diff warned without inventing a package-safety verdict.
Keep AI-assisted drafts separate from evidence-backed, human-owned findings.
Why unsupported input must remain visible instead of silently becoming negative evidence.
How reviewer-facing events, findings, summaries, reports, and audit traces stay schema-validated.
How to explain a dependency policy warning without inventing a package-safety verdict.