Skip to content
View whathehack81's full-sized avatar
🎯
🔬 Building evidence-driven security validation tooling.
🎯
🔬 Building evidence-driven security validation tooling.

Block or report whathehack81

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
whathehack81/README.md

Clara Quiles-Caraballo · whathehack81

Security Research · Detection Engineering · Validation Tooling

I investigate application, cloud, CI/CD, and smart-contract security boundaries. My work centers on deterministic reproduction, attacker-capability analysis, evidence preservation, and responsible disclosure.

I build tooling that helps researchers move from an interesting signal to a defensible conclusion—without confusing scanner output, anomalous behavior, or theoretical risk with demonstrated security impact.

Current work

  • Casper — deterministic validation and evidence runtime for security research. Casper evaluates candidate findings, evidence sufficiency, reproducibility, and advancement decisions; it is intentionally not a vulnerability scanner.
  • SQUIRM — scope-aware endpoint collection and entropy-assisted triage for authorized security assessment.
  • shhh-ai — AI-assisted secret-candidate triage with redaction-by-default output and conservative LLM review.

Research standard

A finding should state:

  1. the security boundary being crossed;
  2. the minimum attacker capability;
  3. a deterministic reproduction path;
  4. observable impact supported by preserved evidence; and
  5. the authorization and scope under which validation occurred.

Uncertainty stays visible. AI review is advisory. Impact is never inferred from a tool label alone.

Areas of focus

Detection engineering · application security · cloud and CI/CD security · smart-contract review · security automation · evidence-driven vulnerability validation

Public activity

All security research represented here is performed on systems I own or under explicit authorization and applicable program rules.

Popular repositories Loading

  1. shhh-ai shhh-ai Public

    name change.

    Python 1

  2. mani-diffy mani-diffy Public

    Forked from chime/mani-diffy

    Go tool that renders Kubernetes manifests from ArgoCD Application templates and commits them to PRs for safer template reviews

    Go 1

  3. Mr-Tron-Recon Mr-Tron-Recon Public

    java research

    Java 1

  4. squirm squirm Public

    A recon tool for cybersecurity & OSINT

    Shell 1

  5. Casper Casper Public

    Security research and tooling workspace for automation, analysis, and testing utilities.

    Python

  6. whathehack81 whathehack81 Public