Larry Peseckis

Security at the intersection of
offense, defense, cloud, and AI.

AI and Cloud Security Architect. Thirty years of mission-critical defense and aerospace systems. DoD Cleared. Now building at the intersection of offensive security, cloud architecture, and AI risk.

01

Work

The proof behind the brand. Real pipelines, honest methodology, documented findings — not marketing language.

attck-pulse

Python · Postgres · MIT

A Python pipeline that ingests public threat intelligence reports from CISA and The DFIR Report, extracts MITRE ATT&CK technique references, and stores them in a queryable Postgres dataset for trend analysis. Built with Wilson confidence intervals for honest precision reporting and documented methodology.

First finding Cross-source technique citation patterns reveal the vantage point of the reporting organization as much as they reveal adversary behavior.

frontier-cyber-risk-taxonomy

Research · Policy · MIT · v0.2

A four-tier classification for cyber assistance from frontier language models, mapped to the emerging industry consensus on capability thresholds. Built as a decision aid for evaluators, red teams, and policy reviewers. Tier definitions map to the Frontier Model Forum's cross-framework analysis, Microsoft's capability tiers, OpenAI's Preparedness Framework, and the regulatory landscape forming around frontier AI cyber capabilities.

Design principle Serve at the most permissive tier the request's plausible legitimate framing supports; escalate when authorization context is stripped out. Refuse-first defaults produce high false-refusal rates and push legitimate practitioners off the tool. The Tier 2 / Tier 3 boundary is where most disputes live, and the framework names it explicitly rather than assuming it away.

llm-attack-atlas

Research · Postgres Private

A structured research corpus of documented LLM attack techniques across the OWASP LLM Top 10, vendor red-team disclosures, and arXiv research papers. The corpus supports analytical queries about category frequency, target-system architecture, and where defensive boundaries need to sit in modern AI system architecture.

Design principle Safety-by-default schema design — every new entry defaults to quarantine, status changes route through an audit trail enforced at the database level, and extraction precision is measured via Wilson confidence intervals against operator-validated ground truth.

v1.5 complete: 34 corpus entries across 3 sources, two validation runs with 100% precision on technique extraction (95% CI lower bound 83.9%). v2 in planning. Repository private during research phase.

burp-cc-bridge

Java · REST API · Burp Suite · PortSwigger · Offensive Security · MIT License

A Burp Suite Community Edition extension that exposes Burp's HTTP capabilities as a localhost REST API on 127.0.0.1:1337 with token auth. Fills the $475/year gap between Community and Professional for practitioners who need scripted automation without the Pro license. 12 endpoints, ~600 lines of Java, MIT licensed. Validated against 4 PortSwigger Web Security Academy labs across 4 vulnerability classes — 203 bridge calls, zero GUI fallbacks, zero failures before the repo went public.

safety-router-transparency

AI Safety · Model Routing · CC BY 4.0

A five-lane model for how a model safety router should explain a reroute to a benign user without handing the trigger to an attacker. Built from a real Fable-to-Opus reroute, it separates the five causes a request can be moved for, and scores transparency on safety, explanation, and reversibility as independent axes.

Core finding Disclosure granularity should track inverse oracle risk: only the restricted-content lane earns strong redaction, and hiding it isn't enough unless content firing is observationally equivalent to it not firing. Otherwise the redaction is defeated by subtraction.

cert-quiz

HTML · JavaScript · no deps

Built because I couldn't find SSCP practice that adapted to my weak areas instead of just reshuffling the same question pool. Started with SSCP, added CCSP — then realized the engine doesn't care what the subject is, so it now covers Linux Essentials and discrete math too. Plain HTML and JavaScript, no dependencies: open index.html and it runs. More sets as the need comes up.

02

Labs

Systematic documentation of offensive and defensive security techniques across 300+ rooms spanning web exploitation, Active Directory, cloud environments, DFIR, and AI/LLM security. Every room gets a writeup. The writeups follow a consistent format: attack chain, detection engineering, key concepts, lessons learned. The habit that made the CJCA report possible.

Full archive on GitHub →

Mindgames — Claude vs CC Experiment

TryHackMe

Empirical comparison of human-in-the-loop vs autonomous AI on the same CTF room. The research question: what does the human variable actually change?

experiment claude-comparison meta ctf

Liberty

HTB Sherlock

Windows DFIR. A .url file in a network share captures Net-NTLMv2 credentials when the folder is opened. No click required.

dfir windows-forensics net-ntlmv2 T1187

Discord Forensics / Operation Dream Job

LetsDefend

Social engineering reconstruction from Chrome cache. Lazarus Group TTPs. The job offer was the pretext. The collaboration request was the collection mechanism.

chrome-cache-forensics social-engineering operation-dream-job T1566

PromptLock AI Ransomware

LetsDefend

A Go binary using a local LLM to generate dynamic encryption payloads at runtime. Signature-based detection is blind to it.

ai-malware llm-ransomware go-binary T1486

AWS VPC Data Exfiltration

TryHackMe

Private subnet is a routing concept, not a security boundary. Four IAM permissions combined turn it into a public attack surface.

aws vpc iam cloud-offensive

Sneaky Patch

TryHackMe

LKM rootkit detection. lsmod vs /sys/module/ comparison. Flag embedded as hex in a kernel module's printk format string.

linux-forensics kernel-rootkit lkm T1014

AS-REP Roasting Investigation

LetsDefend

Full AD kill chain reconstructed from Windows event logs and prefetch artifacts. Three detection signatures that confirm ticket theft, offline crack, and lateral movement.

active-directory kerberos as-rep-roasting lateral-movement

Google Cloud Compromise

LetsDefend

Six log entries, 72 seconds, complete attack chain visible. Data Access logging gap is the defensive finding.

gcp cloud-audit-logs data-exfiltration T1530
04

About

Most security practitioners sit on one side of the wall. Red team or blue team. Compliance or engineering. Cloud or endpoint.

The Integration Thesis is the opposite framing — that offense, defense, cloud, and AI security are one discipline viewed from different angles, and that the most valuable security work happens at the intersections between them. Thirty years of systems administration in classified defense environments taught me how mission-critical infrastructure actually fails. CTF practice, DFIR work, and threat intel research taught me how adversaries actually operate. The portfolio here is what happens when those two bodies of experience start talking to each other.

Credentials

The certification stack runs from CompTIA A+ through SecurityX, ISC2 CC and SSCP, TryHackMe SAL1 and PT1, HackTheBox CJCA, and ITIL 4 — with CISSP as the next target. Each one was earned alongside full-time defense work, not instead of it. The WGU BS in Cybersecurity and Information Assurance (in progress, on track to complete ahead of schedule) fills the formal degree gap. The cert path isn't the point. The judgment that comes from running the material against real labs and real incidents is.

05

Contact

The fastest way to reach me is LinkedIn.