About
I work on the internet’s worst problems for the world’s most comprehensive cloud computing platform. By day I lead a team of extremely competent people doing very serious security things. By night I build weird little tools with names like tracr, dirlstr and mxfckup, ignore several adult responsibilities, and occasionally take over domains that some bloke named Dave misconfigured in 2019 and has not thought about since.
I’ve spent the last decade neck deep in malware, digital forensics and threat intel, which is the industry’s polite phrase for reading other people’s terrible decisions at scale. In one memorable afternoon I watched a plain firewall get rebranded as an “AI-powered zero-trust posture” in a vendor deck, and a device on the same network start quietly exfiltrating to somewhere like totally-not-russia.ru. Only one of those was trying to deceive anyone. I automate anything that looks at me funny, ethically hack things that are doing their best to stay un-hacked, and write tools that make blue teams sweat slightly more than they’d like.
A good chunk of that decade went on phishing, specifically the grubby little kits attackers ship to harvest other people’s passwords. Taking them apart became kitphishr, and then got properly out of hand and became phishtotal.io, a platform I run for hunting phishing at scale and pulling the kits behind it to pieces. It turns out there is no bottom to this particular well.
In my spare time I pretend to be a competitive open water swimmer, because apparently spending all day drowning in logs and packet captures was not wet enough. There is something clarifying about swimming across a freezing, bottomless lake while quietly wondering whether that DNS anomaly from this morning was a typo or the opening move of a breach.
When I’m not in a lake I’m on a rowing machine, chasing a 2k PB that has ignored me for over a year. I spent a decade being warned that AI was coming for my job, so I finally used it to come for my rowing coach’s job instead. I gave it full access to my erg data and it found the hole in two years of my training in about the time it takes to warm up. That turned into a pair of tools and a story about reading your own data.
Most of my tools were born at the precise moment a ceramic mug named Gerald watched me lose an afternoon to a problem that should have taken five minutes. Gerald has witnessed every one of them, and several things far worse. Gerald says nothing, but the silence is always pointed.
My tools solve real problems and answer to questionable names.
- tracr - Finds dangling DNS nameservers at scale
- dirlstr - Discovers open directory listings politely
- webscout - Aerial reconnaissance without the wreckage
- mxfckup - Audits email configs before they audit you
- S3AccountFinder - Attributes S3 buckets to AWS accounts
- psl - Hunts dangling CNAMEs using public suffix boundaries
- kitphishr - Extracts phishing kit metadata
- nsfckup - Identifies NS record vulnerabilities
And a couple that have nothing to do with security and everything to do with going faster.
- ergmcp - Gives an AI your Concept2 logbook so it can actually coach you
- garminmcp - Does the same for your Garmin watch, sleep, HRV and all
I live in the UK, which is ideal for anyone who enjoys grey skies, overpriced pastries, and a constant low-grade inner turmoil over whether to buy a mechanical keyboard they absolutely do not need.
Contact
Find me on GitHub, or use email - cybercdh at gmail dot com. Happy to chat about security, weird bugs, your DNS regrets, or how to make a rowing machine hurt slightly less.