---
title: "Code and Cypher"
canonical: "https://codeandcypher.com/"
description: "Enterprise cybersecurity research by Joshua A. Wortz, CISSP: Zero Trust, cloud security, DevSecOps, threat defense, and AI-security education."
---

# Code and Cypher

> Enterprise cybersecurity research by Joshua A. Wortz, CISSP: Zero Trust, cloud security, DevSecOps, threat defense, and AI-security education.

## Key Sections

- [Blog & Technical Posts](/posts/index.md): Cybersecurity research, engineering deep-dives, and DevSecOps tutorials by Joshua Wortz.

- [Open-Source Projects & Security Tooling](/projects/index.md): Production-grade cybersecurity tools, AppSec automation, detection utilities, and educational labs by Joshua Wortz.

- [Research Papers & Technical Blueprints](/papers/index.md): Formal research papers, technical blueprints, and citable cybersecurity publications by Joshua Wortz.


## Research Papers & Blueprints

- [Acuity Health Enterprise Security Architecture: Hotwash Synthesis](/papers/acuity-health-enterprise-architecture-hotwash-synthesis/index.md) (2026-08-10): Executive synthesis and architectural hotwash of the Acuity Health enterprise security transformation, mapping Zero Trust and NIST governance frameworks.

- [Healthcare Privacy Law, Regulatory Compliance & Cybersecurity Governance](/papers/healthcare-privacy-law-and-cybersecurity-governance/index.md) (2026-08-02): Analysis of HIPAA, HITECH, state privacy statutes, and corporate governance frameworks required for enterprise healthcare cybersecurity programs.

- [Instituting Cyber Threat Intelligence: Predictive Blue-Team Operations](/papers/instituting-cyber-threat-intelligence-in-healthcare/index.md) (2026-07-26): Operational blueprint for establishing a CTI program in a cloud-hosted healthcare provider, featuring threat platform evaluations and dynamic flare response.

- [Healthcare Incident Response, Computer Network Forensics & Containment](/papers/healthcare-incident-response-and-computer-network-forensics/index.md) (2026-07-20): Digital forensics investigation and chain-of-custody framework analyzing an unauthorized EHR database breach involving VIP patient healthcare records.

- [Active Blue-Team Defense, Applied Cryptography & Security Operations](/papers/active-defense-cryptography-and-blue-team-integration/index.md) (2026-07-13): Enterprise research synthesis on active blue-team defense, applied cryptography, and Zero Trust network telemetry operations in high-threat environments.

- [Designing a Secure Software Development Program: Acuity Health AppSec Framework](/papers/designing-a-secure-software-development-program/index.md) (2026-07-06): An engineering framework operationalizing NIST SP 800-218 (SSDF), CI/CD quality gates, and OWASP API security defenses in a healthcare delivery organization.

- [Enterprise Healthcare Security Architecture: The Acuity Health Blueprint](/papers/enterprise-healthcare-security-architecture/index.md) (2026-06-29): Enterprise security architecture and Zero Trust blueprint for an expanding urgent care network under NIST SP 800-207 and the SABSA Multi-Tiered framework.

- [Kerberos Protocol Authentication: Ticket Granting, Mutual Authentication, and Blue Team Hardening](/papers/csol510-kerberos-authentication/index.md) (2026-06-22): Protocol analysis of Kerberos authentication tickets (TGT, TGS), pre-authentication security, and ticket-granting domain defense strategies.

- [Cryptographic Key Metadata, Revocation Protocols, and Key Management Systems](/papers/csol510-metadata-for-keys/index.md) (2026-06-15): Design principles for cryptographic key metadata, enforcing algorithm binding, usage constraints, and automated key expiration policies.

- [Public-Key Cryptography, Digital Signatures, and Certificate Infrastructures](/papers/csol510-public-key-cryptography/index.md) (2026-06-08): Architectural analysis of asymmetric cryptography, Diffie-Hellman key exchanges, and digital certificate validation across untrusted networks.

- [Enterprise Cryptographic Controls: Key Lifecycle, Storage, and Transport](/papers/csol510-cryptographic-controls/index.md) (2026-06-01): Evaluation of cryptographic control selection, implementation trade-offs, and compliance assurances under FIPS 140-3 and ISO/IEC 19790.

- [Hardware Root of Trust: Trusted Platform Module (TPM) Implementation and Verification](/papers/csol510-trusted-platform-module-tpm/index.md) (2026-05-25): Technical analysis of TPM 2.0 cryptographic primitives, secure boot measurement, and platform integrity attestation architecture.

- [Cryptanalysis and Frequency Analysis: Breaking Classical Alphabetic Ciphers](/papers/csol510-breaking-alphabetic-ciphers/index.md) (2026-05-18): Cryptanalytic study of classical substitution ciphers, frequency analysis, and mathematical foundations of modern symmetric cryptography.

- [Security Models and Kerckhoffs's Principle in Applied Cryptography](/papers/csol510-security-models-and-kerchhoffs-principle/index.md) (2026-05-11): Foundational review of Kerckhoffs's Principle, Shannon's cipher security models, and why security-by-obscurity consistently fails.

- [Enterprise Cyber Threat Intelligence Program Plan: Operational Framework and Platform Architecture](/papers/csol580-part-i-cyber-threat-intelligence-program-plan-propos/index.md) (2026-04-06): Operational proposal for establishing an enterprise Cyber Threat Intelligence (CTI) capability, platform architecture, and collection strategy.

- [Adversary TTP Mapping and Attack Path Analysis Using the MITRE ATT&CK Framework](/papers/csol580-analyzing-cyber-attacks-using-the-mitre-att-ck-matri/index.md) (2026-03-23): Adversary tactics, techniques, and procedures (TTPs) mapping using MITRE ATT&CK to reconstruct enterprise identity and cloud intrusion paths.

- [Strategic Value of Threat Intelligence: Cost Savings, Risk Reduction, and Security Optimization](/papers/csol580-strategic-cost-savings-productivity-enhancement-and/index.md) (2026-03-23): Executive business case demonstrating CTI ROI, incident cost reduction, and SOC productivity enhancement through automated intelligence feeds.

- [Cyber Threat Intelligence Triage and Executive Response Report](/papers/csol580-intelligence-triage-and-response-report/index.md) (2026-03-16): Executive threat intelligence triage report analyzing an advanced persistent threat campaign and delivering defensive response playbooks.

- [Forensic Investigation Findings: Incident Reconstruction, Root Cause, and Expert Witness Report](/papers/csol590-presentation-of-findings/index.md) (2026-02-16): Forensic investigation report and expert witness documentation synthesizing digital evidence, chronological timeline reconstruction, and findings.

- [Standard Operating Procedures (SOP) for Digital Forensics and Evidence Handling](/papers/csol590-implementing-standard-operating-procedures-for-handl/index.md) (2026-02-16): Standard operating procedures (SOP) for digital forensics evidence intake, forensic imaging, chain-of-custody tracking, and legal hold compliance.

- [Legal Admissibility of Digital Evidence: Federal Rules of Evidence and Daubert Standards](/papers/csol590-understanding-digital-evidence/index.md) (2026-02-09): Legal admissibility standards for digital evidence under Federal Rules of Evidence, Daubert criteria, and ISO/IEC 27037 forensic guidelines.

- [Mobile Device Forensics: Extraction, Decoding, and SQLite Database Analysis](/papers/csol590-analyze-a-cell-phone-image/index.md) (2026-02-02): Digital forensics analysis of a mobile device image, decoding SQLite databases, call logs, and deleted communication artifacts.

- [Forensic Artifact Analysis Using Autopsy: File System Reconstruction and Timeline Carving](/papers/csol590-examine-the-evidence-using-autopsy/index.md) (2026-01-26): Forensic artifact investigation using Autopsy, examining file system timestamps, deleted inode carving, and keyword index analysis.

- [Digital Forensics: Evidence Acquisition, Chain of Custody, and Volatile Memory Preservation](/papers/csol590-preservation-and-acquisition-of-the-evidence/index.md) (2026-01-19): Digital evidence acquisition and live volatile memory preservation procedures ensuring forensic integrity and cryptographic hash verification.

- [Enterprise Incident Response Plan and RACI Governance Matrix](/papers/csol590-incident-response-plan-responsibility-chart/index.md) (2026-01-12): Incident response governance framework establishing RACI matrices, triage escalation paths, and executive communication protocols.

- [Software Security Metrics, Technical Debt Quantification, and Program Maturity](/papers/csol560-risks-and-metric-in-software-systems/index.md) (2025-12-08): Quantitative framework for software security metrics, technical debt measurement, and AppSec maturity assessment (OpenSAMM/BSIMM).

- [Ransomware Simulator: Cryptographic Attack Modeling and Application-Level Defenses](/papers/csol560-ransomware-simulator/index.md) (2025-11-30): Engineering design and safe execution of a controlled ransomware simulation framework to validate endpoint detection and backup resilience.

- [Static Application Security Testing (SAST) and Secure Web Application Design](/papers/csol560-static-analysis-of-a-website-secure-design/index.md) (2025-11-24): Static application security testing (SAST) methodology and secure web application architecture aligned with OWASP Top 10 guidelines.

- [Threat Modeling and Architectural Risk Analysis: STRIDE and DREAD Applications](/papers/csol560-risks-threats-vulnerabilities/index.md) (2025-11-17): Architectural threat modeling applying STRIDE and DREAD frameworks to identify vulnerabilities and prioritize engineering mitigations.

- [Secure Software Development Life Cycle (SSDLC): Comparative Analysis of Microsoft SDL and Apple Ecosystems](/papers/csol560-secure-software-development-life-cycle-ssdlc-microso/index.md) (2025-11-14): Comparative analysis of Secure Software Development Life Cycle models, contrasting Microsoft SDL with Apple secure development practices.

- [Compromised Network Indicators and Secure Application Risk Mitigations](/papers/csol560-compromised-network-indicators-and-risk-mitigations/index.md) (2025-11-03): Technical analysis of Indicators of Compromise (IoCs), lateral movement detection, and host-based risk mitigation playbooks.

- [Secure Software Development Life Cycle (SDLC) Phase Analysis and Control Gates](/papers/csol560-csol-560-module-1-assignment-table/index.md) (2025-10-27): Comparative evaluation of eight software development life cycle (SDLC) models across requirement volatility, risk management, and security control integration.

- [Supply Chain Cyber Attack Investigation: Root Cause Analysis, Impact Scoping, and Remediation](/papers/csol570-final-assignment-7-1-supply-chain-attack-investigati/index.md) (2025-10-18): Forensic root cause analysis and scoping of a decentralized software supply chain compromise, establishing containment and vendor remediation.

- [Post-Exploitation Detection and Network Reconnaissance Signature Analysis](/papers/csol570-post-exploitation-and-nmap-scanning/index.md) (2025-09-29): Technical analysis of network reconnaissance signatures and post-exploitation detection using telemetry from host and network sensors.

- [Open Source Intelligence (OSINT) and Mobile Telemetry for Blue Team Defense](/papers/csol570-open-source-and-mobile-intel-for-security/index.md) (2025-09-20): Open-source intelligence (OSINT) and mobile telemetry collection framework for proactive threat hunting and attack surface monitoring.

- [Honeypots and Deception Technologies: Strategic Attacker Disruption and Early Warning](/papers/csol570-honeypots-and-deception-techniques/index.md) (2025-09-14): Strategic evaluation of honeypots, honeytokens, and active deception technology to disrupt attacker reconnaissance and generate high-fidelity alerts.

- [Cybersecurity and International Law: State Sovereignty, Tallinn Manual, and Extraterritorial Jurisdiction](/papers/csol540-cybersecurity-and-international-law-case-analysis/index.md) (2025-08-11): International law analysis applying the Tallinn Manual, state sovereignty, and rules of engagement to nation-state cyber warfare.

- [HyperBeard COPPA Compliance Analysis: Children's Online Privacy Enforcement](/papers/csol540-hyperbeard-coppa-compliance-analysis/index.md) (2025-08-01): Regulatory case study examining FTC enforcement against HyperBeard for COPPA violations involving behavioral advertising to minors.

- [The Blue Team Mindset: Active Defense, Telemetry Engineering, and Defensive Posture](/papers/csol570-the-blue-team-mindset/index.md) (2025-08-01): Exploration of active blue-team defense methodologies, telemetry engineering, and continuous adversary engagement in enterprise SOCs.

- [DMCA and IoT Security: Legal Analysis of Reverse Engineering, Firmware Access, and Copyright Protections](/papers/csol540-introduction/index.md) (2025-07-28): Analyzes DMCA and EULA case law (Davidson v. Jung, Philips, MDY v. Blizzard), applying judicial doctrines to IoT firmware access and security research rights.

- [Comparative Analysis of Data Breach Notification Statutes and Litigation Risk](/papers/csol540-analyzing-data-breach-laws-and-their-impact/index.md) (2025-07-21): Analysis of state and federal data breach notification statutes, statutory timelines, and consumer notification requirements.

- [Cross-Sector Compliance Analysis: SEC Disclosures, HIPAA Security Rule, and FERPA](/papers/csol540-compliance-analysis-of-sec-hipaa-and-ferpa-cybersecu/index.md) (2025-07-14): Comparative compliance mapping across SEC cybersecurity disclosure rules, HIPAA Security Safeguards, and FERPA educational privacy.

- [Regulatory Compliance and Enforcement: FTC, SEC, and State AG Jurisdictions](/papers/csol540-analyzing-cybersecurity-compliance-and-enforcement/index.md) (2025-07-07): Comparative legal analysis of regulatory enforcement actions, consent decrees, and legal liabilities following corporate data breaches.

- [Cybercrime Jurisprudence: Statutory Analysis of the CFAA and Wire Fraud Act](/papers/csol540-cybercrime-analysis/index.md) (2025-06-28): Case study of Roman Seleznev's card theft ring, examining point-of-sale SQL injection exploits, foreign extradition, and federal cyber fraud prosecution.

- [Quantum-Ready Risk Management Plan: Post-Quantum Cryptography Migration Strategy](/papers/csol530-quantum-ready-risk-management-plan/index.md) (2025-06-22): Strategic risk management roadmap for transitioning enterprise cryptography to post-quantum standards before cryptanalytic breakthroughs.

- [Automating AI Security Risk Assessment, LLM Governance, and Threat Detection](/papers/csol530-automating-ai-security-risks/index.md) (2025-06-15): Framework for identifying and mitigating AI security risks, prompt injection vectors, and automated model evaluation pipelines.

- [Cybersecurity Governance Frameworks, Regulatory Compliance, and Maturity Auditing](/papers/csol530-cybersecurity-governance-and-compliance/index.md) (2025-06-04): Governance framework analyzing policy hierarchies, compliance mapping, and audit readiness across regulated enterprise environments.

- [Designing Robust Security Controls for Cloud and IoT Ecosystems](/papers/csol530-designing-robust-security-controls-for-cloud-and-iot/index.md) (2025-06-02): Security architecture blueprint specifying robust isolation controls, mutual TLS, and device attestation for cloud and IoT ecosystems.

- [Designing a Zero Trust Strategy for Third-Party and Vendor Risk Management](/papers/csol530-designing-a-zero-trust-strategy-for-third-party-risk/index.md) (2025-05-26): Zero Trust architecture blueprint enforcing dynamic context-based access and least privilege for third-party vendors and contractors.

- [Enterprise Risk Analysis Report: Quantitative and Qualitative Risk Assessment](/papers/csol530-creating-a-risk-analysis-report/index.md) (2025-05-17): Methodology for synthesizing technical vulnerability data into executive-ready risk analysis reports with actionable remediation roadmaps.

- [Fundamentals of Cyber Governance: Alignment, Oversight, and Policy Enactment](/papers/csol530-fundamentals-of-cyber-governance/index.md) (2025-05-11): Foundations of cybersecurity governance, board oversight, risk appetite formulation, and regulatory accountability structures.

- [Component Architecture Blueprint: Security Micro-Segmentation and Service Meshes](/papers/csol520-blueprint-for-modern-component-architecture/index.md) (2025-04-07): Component-level security blueprint detailing zero-trust network zones, API gateways, and defense-in-depth isolation mechanisms.

- [Physical and Environmental Security Architecture for Enterprise Facilities](/papers/csol520-developing-a-physical-security-architecture/index.md) (2025-03-31): Physical and infrastructure security architecture covering data center zoning, environmental controls, and hardware tamper defense.

- [Logical Security Architecture: Zero Trust Zones, Segmentations, and Access Controls](/papers/csol520-creating-the-logical-architecture/index.md) (2025-03-24): Logical security architecture framework defining data flow boundaries, authorization services, and access control matrices.

- [Conceptual Security Architecture: Enterprise Risk Modeling and Defense Boundaries](/papers/csol520-conceptual-security-architecture/index.md) (2025-03-17): Foundational conceptual security architecture translating organizational missions into verifiable enterprise protection boundaries.

- [Defining Strategic Goals, Business Drivers, and Security Objectives](/papers/csol520-defining-goals-and-objectives/index.md) (2025-03-10): Strategic governance guide for establishing measurable security goals, KPI metrics, and executive cyber risk alignment.

- [A Conceptual Model of Enterprise Security Architecture](/papers/csol520-a-conceptual-model-of-architecture/index.md) (2025-03-03): Conceptual security architecture model synthesizing business drivers, threat contexts, and high-level control objectives using SABSA.

- [Developing a Comprehensive Cybersecurity Program Plan](/papers/csol500-final-project-developing-a-cybersecurity-program-pla/index.md) (2025-02-24): Comprehensive enterprise cybersecurity program plan integrating ISO 27001, NIST CSF governance, and defense-in-depth operational controls.

- [Vulnerability Analysis: Threat Identification, Severity Scoring, and Remediation](/papers/csol500-vulnerability-analysis/index.md) (2025-02-16): Methodology for automated vulnerability scanning, common vulnerability scoring (CVSS), and prioritized risk remediation in production networks.

- [Cloud Security Risks and Shared Responsibility Mitigations](/papers/csol500-cloud-security-risks-mitigations/index.md) (2025-02-10): Evaluation of cloud shared responsibility models, identity governance, and multi-tenant architectural risk mitigations for enterprise workloads.

- [Hacking Wall Street: Financial Sector Cyber Threats and Attack Vectors](/papers/csol500-hacking-wall-street/index.md) (2024-01-27): Examines financial sector cyber threats, evaluating simulated attack rehearsal efficacy and data loss prevention across major banking infrastructures.

- [Taxonomy of Enterprise Cyber Risk: Strategic, Operational, and Technical Analysis](/papers/csol500-risk-types/index.md) (2024-01-20): Taxonomy and comparative assessment of operational, technological, financial, and reputational cyber risk categories across enterprise systems.

- [The Six Phases of the ADDIOI Model: Foundations of Cybersecurity Program Design](/papers/csol500-the-six-phases-of-the-addioi-model/index.md) (2024-01-12): Explains Schreider's six-phase ADDIOI cybersecurity model (Align, Design, Develop, Implement, Operate, Improve) and principles for enterprise security programs.


## Technical Articles & Posts

- [Working Backwards from Error Logs: Reverse Engineering the Tableau-to-Fabric OAuth Breakdown](/posts/reverse-engineering-tableau-to-fabric-oauth/index.md) (2026-10-02): Reverse engineer Tableau to Fabric OAuth failures, decode AADSTS650052, and build hardened, least-privilege Entra ID runbooks with KQL and PowerShell.

- [Modernizing the Academic Knowledge Graph: Canvas Sync Bridge v0.4.0, Hybrid Ingestion, and Official Obsidian Compliance](/posts/canvas-to-obsidian-local-first-coursework-bridge/index.md) (2026-09-18): Architecting a hybrid, local-first bridge from Canvas LMS to Obsidian with v0.4.0 compliance, zero telemetry, and decoupled extensions.

- [Bridging the Browser-to-Boundary Gap: From Client-Side SPA State Reconnaissance to Safe Harbor Verification](/posts/client-side-spa-recon-and-safe-harbor-verification/index.md) (2026-09-12): How to hunt client-side SPA state in DevTools with StateHunter and enforce mathematical scope boundaries and Safe Harbor adherence with AuditGuard.

- [Triage Under Fire: The Lean Team's 48-Hour Hardening Blueprint for September 2026 Patch Tuesday](/posts/the-lean-teams-48-hour-patch-tuesday-blueprint/index.md) (2026-09-09): How lean security teams triage Patch Tuesday, filter the firehose, harden Kerberos identity boundaries, and contain critical flaws in the first 48 hours.

- [My Teaching Philosophy: Building Accessible AI Security Education](/posts/teaching-philosophy-ai-security-overview/index.md) (2026-08-30): Explore an accessible teaching philosophy for AI security using Universal Design for Learning (UDL), multimodal labs, and zero-cost open educational resources.

- [Teaching AI Security: Hands-On LLM Hardening with Docker Desktop and Security Gateways](/posts/ncyte-ai-security-webinar-llm-hardening/index.md) (2026-08-30): A complete guide to teaching AI security on student laptops with zero API costs using Docker, Ollama, and a Python security gateway against prompt injection.


## Hands-On Series & Tracks

- [Hands-On AI Security: Policy-as-Code with Open Policy Agent and Rego](/series/hands-on-ai-security/part-4-policy-as-code-open-policy-agent-rego/index.md) (2026-10-01): Connect Open Policy Agent (OPA) to your AI security gateway, evaluate context classifications in real time, and generate audit-ready security block logs.

- [Acuity Health: Part 4 — CI/CD Quality Gates & ISO 27001 Risk](/series/acuity-health-security-architecture/part-4-automated-ci-cd-quality-gates-iso27001-risk/index.md) (2026-09-29): Enforce automated CI/CD quality gates, track SLAs, and execute an actionable 10-step ISO 27001:2013 risk assessment across cloud healthcare workloads.

- [Hands-On AI Security: Blue Teaming and Building the Security Gateway](/series/hands-on-ai-security/part-3-blue-teaming-building-the-security-gateway/index.md) (2026-09-24): Construct an external security gateway in Flask to inspect incoming prompts, enforce guardrails, and intercept leaked secrets before they reach the browser.

- [Acuity Health: Part 3 — STRIDE Threat Modeling & BOLA Elimination](/series/acuity-health-security-architecture/part-3-threat-modeling-stride-api-security/index.md) (2026-09-22): Map trust boundaries with STRIDE during sprint grooming, protect data flows, and prevent Broken Object Level Authorization (BOLA) in modern healthcare APIs.

- [Hands-On AI Security: Red Teaming Piper with 5 Prompt Injection Vectors](/series/hands-on-ai-security/part-2-red-teaming-piper-prompt-injection-vectors/index.md) (2026-09-17): Attack the Piper chatbot across 5 prompt injection categories, testing vulnerabilities, boundary bypasses, and hardened model variants in a local AI testbed.

- [Acuity Health: Part 2 — Zero Trust DevSecOps & NIST SSDF](/series/acuity-health-security-architecture/part-2-architecting-zero-trust-devsecops/index.md) (2026-09-15): Operationalize NIST SP 800-218 (SSDF) and Zero Trust Architecture across cloud-native development environments, ephemeral CI/CD pipelines, and supply chains.

- [Hands-On AI Security: Building a Zero-Cost Local LLM Lab with Docker, Ollama, and Piper](/series/hands-on-ai-security/part-1-zero-cost-local-llm-lab/index.md) (2026-09-10): Architect a reproducible local AI red/blue team lab using Docker, Ollama, and the vulnerable Piper chatbot on standard 8GB RAM student laptops.

- [Acuity Health: Part 1 — Securing the 2 AM Urgent Care (Zero Trust for Distributed Clinics)](/series/acuity-health-security-architecture/part-1-enterprise-security-architecture/index.md) (2026-09-08): Secure decentralized urgent care clinics with a lean IT team using port-level dynamic VLANs, gloved-hand MFA, EDR micro-isolation, and immutable WORM backups.


## Open-Source Projects & Tooling

- [Hugo DevSecOps Starter](https://github.com/SixFiveMil/hugo-devsecops-starter) (Production Stable): Universal, platform-agnostic, zero-trust static publishing engine with automated DevSecOps gates. — A production-grade, zero-trust static publishing framework featuring automated Gitleaks secret scanning, 33+ headless Python DevSecOps quality gates, shift-left CLI tooling, RFC 9116 security.txt validation, and pluggable edge deployment adapters.

- [AuditGuard](https://github.com/SixFiveMil/auditguard) (Production Stable): Compliance-First Scope Enforcement & Audit Automation Framework — A terminal framework designed for authorized security research under VDP and bug bounty engagements. Mathematically prevents out-of-scope network traffic, executes Nuclei-compatible YAML diagnostics, audits dual-role authorization matrices (IDOR/BOLA), calculates FIRST.org CVSS v3.1 scores, and generates Disclose.io Safe Harbor proof-of-adherence certificates.

- [StateHunter](https://github.com/SixFiveMil/statehunter) (Production Stable): In-Browser SPA State & DOM Security Reconnaissance — A high-performance Chrome Manifest V3 DevTools extension for application security engineers and penetration testers. Performs real-time client-side runtime JS analysis, de-obfuscates hidden Next.js/Nuxt/Remix chunk manifests, audits and replays postMessage handlers, detects in-memory secrets and high-entropy keys, and exports directly to AuditGuard YAML.

- [Sentinel-Inventory](https://github.com/SixFiveMil/Sentinel-Inventory) (Reference Implementation): Log Analytics Schema Discovery & Sentinel Rule Coverage Auditor — Enterprise discovery and audit utility for Microsoft Sentinel and Azure Log Analytics. Discovers table schemas, auto-resolves ARM workspace hierarchies, cross-references deployed analytics rules against Content Hub solution templates, and outputs phased, risk-prioritized rule enablement plans.

- [WordPress MCP Server](https://github.com/SixFiveMil/wp-mcp-server) (Production Stable): Model Context Protocol Server for WordPress Publishing — A production-grade Model Context Protocol (MCP) server enabling Claude, Gemini, and agentic AI systems to securely query, draft, review, and publish technical publications via the WordPress REST API.

- [Securing-AI Sandbox](https://github.com/SixFiveMil/Securing-AI) (Educational Lab): Hands-On Local LLM Prompt Injection & Defense Lab — A containerized Red Team / Blue Team lab designed for teaching practical LLM defenses. Uses Docker Compose, local Ollama models, and a Python security gateway to demonstrate the necessity of layered defense-in-depth against prompt injection and data exfiltration.

- [decoding Engine](https://github.com/SixFiveMil/decoding) (Educational Lab): Automated Cryptanalysis & Stochastic Hill-Climbing Decoder — Pure Python 3 cryptanalysis tool implementing frequency analysis, stochastic hill-climbing optimization, and Kasiski / Index of Coincidence analysis to break mono-alphabetic and poly-alphabetic ciphers.

- [Canvas to Obsidian Sync](https://github.com/SixFiveMil/obsidian-canvas-sync) (Active Beta): Hybrid local-first bridge syncing Canvas LMS courses, grades, files, and discussions into Obsidian. — Bridges academic coursework directly from Canvas LMS into Obsidian as clean, linked Markdown notes. Features a decoupled hybrid architecture pairing an official guidelines-compliant Obsidian plugin with a standalone Manifest V3 browser extension. Supports direct Canvas REST API syncing (Desktop & Mobile) and zero-token browser extraction for locked-down institutions. Validated with official obsidianmd/obsidian-workflows, SLSA build provenance attestations, and 100% zero-telemetry local execution.

- [Canvas to Obsidian Extension](https://github.com/SixFiveMil/canvas-to-obsidian-extension) (Active Beta): Multi-browser Manifest V3 companion extension for zero-token session course extraction. — Standalone Manifest V3 browser extension for Chrome, Brave, Edge, Arc, and Firefox. Extracts authenticated Canvas LMS course hierarchies, syllabi, assignments, grades, and discussion trees directly from active browser session cookies without requiring administrative API tokens. Bridges data securely over link-local loopback (127.0.0.1:27125) into Obsidian.

