Skip to content
View MSAdministrator's full-sized avatar
💭
Building Thangs
💭
Building Thangs

Organizations

@sublime-security

Block or report MSAdministrator

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MSAdministrator/README.md

Header

Welcome!

GitHub X LinkedIn Blog

Profile Views

Just like information security, I am socio-technical: I build tools and systems that solve real problems, automate unnecessary toil, and help people make better security decisions.

I am a threat research and detection engineer with 14+ years of experience across security operations, DFIR, security architecture, product leadership, and software engineering. I have built open-source tools, led products used by more than 18 million people, and helped design and operate Go and Python services that process billions of security events daily.

My current work sits at the intersection of threat research, phishing defense, behavioral detection, security automation, and agentic systems. I enjoy taking ambiguous security problems and turning them into reliable detections, useful tooling, scalable services, and workflows that keep human judgment in the loop.

Earlier in my career, I worked in phishing defense, vulnerability management, digital forensics, incident response, and enterprise systems administration. That foundation, including Active Directory, Group Policy, PowerShell, endpoint management, and server administration, still shapes how I approach security engineering today.

I am GIAC GCWN certified and previously held the GCFA. I write, present, and build in the open at letsautomate.it.

What I Work On

Defensive Systems — Detection engineering, validation, adversary simulation, security automation, and operational reliability.

Security Intelligence — Threat research, phishing infrastructure, behavioral analysis, capability discovery, and adversary-focused investigation.

Cognitive Security Systems — Agentic tooling, knowledge representation, orchestration, reasoning, and human-in-the-loop security workflows.

Engineering — Go and Python services, distributed systems, high-volume event processing, APIs, automation, and operational tooling.

Current Role

Threat Research Engineer

Sublime Security (June 2026 to Present)

I research threats and build detections, tooling, and frameworks to improve phishing defense through better behavioral detection and analyst-facing workflows.

Background

14+ years across Sublime Security, AppOmni, Red Canary, Swimlane, Cofense, and the University of Missouri — spanning security operations, DFIR, detection engineering, security architecture, product leadership, and software engineering. Earlier work included Windows infrastructure, Active Directory, Group Policy, PowerShell, vulnerability management, and incident response.

Full history: letsautomate.it/page/about

Open Source

I have built and contributed to open-source projects used across the security engineering community. I am also an official maintainer of Atomic Red Team.

  • pyattck — Python package for working with MITRE ATT&CK
  • atomic-operator — Python framework for executing Atomic Red Team tests
  • soc-faker — Synthetic data generation for security operations and automation
  • opencti-enrichment — Go service for OpenCTI observable enrichment
  • ai-router — Python CLI for routing local Ollama models based on available system resources

More open-source projects · GitHub

Research & Writing

I write about security engineering, detection, automation, software systems, defensive research, and the social and technical implications of AI at letsautomate.it.

Latest Posts

Publication

Beyond the Prompt: The Social Costs of Generative Artificial Intelligence

Published in the Business, Entrepreneurship & Tax Law Review, Vol. 10, Issue 1 (2026).

Recognitions

  • Official maintainer of Atomic Red Team
  • Past President and Board Member, Central Missouri InfraGard chapter
  • SC Media Reboot Leadership Awards 2019 — Influencer
  • Contributing author to Tribe of Hackers: Blue Team

Certifications

  • GIAC Certified Windows Security Administrator (GCWN)
  • Previously held GIAC Certified Forensic Analyst (GCFA)

Selected Talks

Full list: letsautomate.it/page/presentations

GitHub Stats

MSAdministrator GitHub Stats MSAdministrator GitHub Streak

Pinned Loading

  1. swimlane/pyattck swimlane/pyattck Public archive

    A Python package to interact with the Mitre ATT&CK Framework

    Python 480 93

  2. goattck goattck Public

    A Golang CLI for the MITRE ATT&CK Framework

    Go 15

  3. ai-router ai-router Public

    ai-router is a python cli tool to route local Ollama models based on your local system specifications.

    Python

  4. domain-profiler domain-profiler Public

    A Python package and CLI tool to gather data about a given domain

    Python

  5. go-mmdb-extender go-mmdb-extender Public

    A Golang application to extend MMDB with CZDS data

    Go