Skip to content
View SSH-PuR66's full-sized avatar

Highlights

  • Pro

Block or report SSH-PuR66

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
SSH-PuR66/README.md

Sergio Rodriguez — threat analyst & security toolsmith

I build the defensive tooling analysts actually use, and I'm aiming it at federal cyber operations — taking cybercrime off the board.

Current research

CVE Replay · Study and results

Independent offline reproduction of the published CVE-2026-44431 redirect-header issue, originally reported by christos-cantina-security. The harness compares urllib3 2.6.3 and 2.7.0. On 27 September 2026, all 12 expected outcomes matched: six cases per release, including the affected behavior and benign controls. Inspect the passing regression workflow.

Call Boundary · Experiment and test record

A local authorization gate that binds a signed approval to one actor, audience, tool, target, complete arguments, time window, and nonce. The 27 September 2026 run passed 56 tests and 29 controlled vectors, including replay across processes and restarts. Python, HMAC-SHA256, and SQLite. Inspect the passing regression workflow.

Binary Boundary · Native and decompiler study

An original C fixture comparing Boolean decoding and unsigned range checks across O0 and O2 builds. Native execution and Ghidra exports expose where recovered types differ from the source contract. A fresh 27 September 2026 rerun matched the recorded native results and decompiler output. It covers every byte value and 21,728 range inputs per build; the full 32-bit input space is not exhausted.

Proposed work — Filament PR #1

Signing checks tied to the selected app, identity, and connected device. The open pull request invalidates approval when an input changes and discards stale responses. Portable CI passed on 12 September.

Earlier projects — Tools · DetectLab · PolicyScout / ArmSky

Credentials — Cisco Certified in Cybersecurity · (ISC)² Candidate · Blue Team Junior Analyst · 18 Anthropic AI certificates

Working with — Python · FastAPI · scikit-learn · Docker · Cloudflare · Neo4j · Elasticsearch · the MITRE ATT&CK framework

How I work — controlled reproductions, inspectable test records, and explicit limits on what the evidence establishes.

Hudson Valley / NYC metro · federal cyber operations · sergio.w.rdz@gmail.com · sergrdz.pages.dev

Popular repositories Loading

  1. LiveContainer-Plus LiveContainer-Plus Public

    LiveContainer fork: app groups, backup/restore, certificate health monitoring, and bulk AltStore source import

    Swift 7

  2. FlowForge FlowForge Public

    HTML

  3. Tools Tools Public

    Python

  4. LicenseLoop LicenseLoop Public

    Python

  5. CivicPulse CivicPulse Public

    Python

  6. PuR63-s-portfolio PuR63-s-portfolio Public