I make stuff, break stuff, and protect stuff from getting hacked.
Security engineering, incident response, offensive + defensive, lots of automation, occasionally questionable humour.
- Using AI, Agentic workflows, LLMS, etc. around red/purple teaming
- Building practical security tooling (stuff teams will actually use)
- Security automation / agentic workflows (making the boring bits faster + repeatable)
- Detection + response engineering (signal quality > alert spam)
- security-skills - A collection of Claude Code skills that help security teams stay secure
- shhgit โ Secrets detection used by 100s of companies in their CI/CD pipelines
- cracke-dit โ Password auditing for AD environments
- bucket-stream โ Bug bounty hunting tool to find interesting S3 buckets by monitoring cert transparency logs
- the-endorser โ OSINT tool for mapping LinkedIn endorsement relationships
I publish security research + build open source. Sometimes it gets picked up by the media.
- darkport.co.uk
- twitter/x: @darkp0rt
- email: paul@darkport.co.uk




