Skip to workbench

THE WORKBENCH / OPEN FOR INSPECTION

Explore the work.
Pull on a thread.

Working interfaces. Inspectable code. A clear account of what each experiment does—and where its evidence ends.

SR / 02

Choose a project.
Inspect the decisions.
Try it for yourself.

PROJECT EXPLORER PUBLIC DEMOS & SOURCE

01 / RESEARCH FIXTURE

Evidence lab

Three small counterexamples: malformed Boolean bytes, event attribution, and execution gaps.

labs/evidence/
An illustrative path from an input, through a boundary, to inspectable evidenceINPUTBOUNDARYEVIDENCE
READY WHEN YOU AREEvidence lab

The interactive page loads when you choose Load preview.

Open full page ↗

Preview not loaded. The full page is always available.

WHAT TO INSPECT
Change a controlled input, compare the original assumption with the corrected check, and inspect the Python reproducer.
THE BOUNDARY
Synthetic fixtures demonstrate bounded software behavior. They do not establish a third-party vulnerability or trading profitability.

NEXT / READ THE IMPLEMENTATION

The tools behind
the questions.

Python projects with explicit methods,
evaluation fixtures, and limits at source.

01 / EXPOSURE

RangeCheck

Concurrent discovery, service fingerprinting, and explainable finding rules. An exposed service is an observation to investigate.

PythonAsyncReports
Inspect source ↗Read methodology ↗
02 / DETECTION

Detect Lab

ATT&CK-mapped detection rules and time-window correlation. Published fixtures and critiques make the logic reviewable.

PythonRulesRegression tests
Inspect source ↗Read critique ↗
03 / RETRIEVAL

PolicyScout

Hybrid retrieval and cited answers with a sample evaluation corpus. The critique documents decisions, corrections, and limits.

PythonRetrievalEvidence
Inspect source ↗Read critique ↗

Sample scores describe the supplied fixtures. They are not claims of production coverage, accreditation, or client outcomes.

FOLLOW THE REASONING

Read the investigation.

PUBLIC DATA / RESEARCH VIEWS

Keep the source
in the picture.

Expand a view to request its public-data snapshot.
Methods and limitations stay beside the numbers.

01Threat indicatorsCISA KEV · Feodo Tracker · ThreatFox

Public indicators returned by the existing feed service: CISA KEV, Feodo Tracker, and ThreatFox. Check the source timestamp and coverage before interpreting the sample.

Open this panel to load its public data.

Recently added to KEV

CISA KEV

Loading current CVEs…

Active botnet C2

Feodo Tracker

Loading live C2 servers…

Fresh indicators

ThreatFox

Loading recent IOCs…

Public-source snapshot · no automatic polling
02Emerging vulnerabilitiesNVD · FIRST EPSS · CISA

Recent NVD entries ranked by FIRST EPSS, with CVSS context and KEV membership. EPSS estimates exploitation probability over the next 30 days. A score or a missing catalog entry does not establish whether a particular system is safe.

Open this panel to load its public data.

Ranking newest CVEs by exploitation probability…

Ranking = EPSS probability first, then CVSS severity, then recency. EPSS via FIRST.org; scores shift daily as exploitation signal accrues. This is public-data analysis, not a claim of private discovery.

Public-source snapshot · no automatic polling
03Disclosure to the KEV catalogPublication dates · catalog inclusion · limits

This board compares a vulnerability's NVD publication date with the date CISA added it to the Known Exploited Vulnerabilities catalog: max(0, KEV dateAdded − NVD published). The interval describes time to catalog inclusion. It does not date the first exploit or measure how long a system was safe to leave unpatched. Only entries matched across the two sources are included.

Open this panel to load its public data.

Catalog interval by year

median days, by KEV addition year

Loading…

Catalog interval by vendor

2023+, shortest first

Loading…

METHOD & LIMITS

Headlines use matched entries added to KEV from 2023 onward; the yearly chart also includes earlier additions. Historical backfills and delays in publication or cataloging affect this interval in every year. dateAdded is the catalog addition date, not the first exploitation date. Intervals at or below zero are displayed as zero; they do not establish a zero-day exploit. KEV is a selected catalog, and missing source records can reduce coverage. These figures describe catalog history and do not establish a safe patching window.

Public-source snapshot · no automatic polling
04Extortion activityAggregate counts · ransomware.live

Posting counts, group activity, and sector summaries from ransomware.live. These are aggregate observations of a selected public feed, not a census of incidents or independently verified victim claims.

Open this panel to load its public data.

Operator tempo

postings per crew

Loading…

Sector selection

who they're picking

Loading…

Geography

victim country

Loading…

COLLECTION ETHICS

This view presents aggregate counts. Victim names and hidden-service addresses are not displayed. The counts describe source postings and do not establish the number of confirmed breaches.

Public-source snapshot · no automatic polling
Read the threat-intelligence research ↗

THE PERSON BEHIND THE WORK

Serious about
the details.

I’m Sergio Rodriguez, a security tool builder from New York’s Hudson Valley, studying Cybersecurity at Iona University with a focus on Security Threat & Analysis.

More about me ↗

CONTINUE THE CONVERSATION

Let’s look closer.

sergio.w.rdz@gmail.com ↗

Résumé ↗GitHub ↗LinkedIn ↗

Project preview