DFIR & Detection Engineering Β· Tokyo, Japan
Building autonomous detection systems and architectural security guarantees. Currently exploring agentic DFIR β MCP-based forensic agents that encode the reasoning pattern of a senior analyst as architecture, not as a prompt.
- Digital Forensics & Incident Response Β· Windows / macOS / Linux
- Detection Engineering Β· MITRE ATT&CK coverage modeling, Sigma
- DevSecOps & Security Automation
- Agentic AI for Security Β· MCP, audit-chained reasoning loops
Autonomous DFIR agent that thinks like a senior analyst. Architecture-first, not prompt-first. 60 typed forensic MCP tools (35 native + 25 SIFT Workstation adapters) across 11 / 12 MITRE ATT&CK tactics, 31 / 31 tests passing on a fresh clone (CI green on Python 3.10/3.11/3.12/3.13), 1182-line senior-analyst playbook v3 synthesizing Mandiant + Bianco + Diamond + Palantir ADS + MaGMa UCF + TaHiTI hunt cycle (42 references). Read-only MCP boundary makes destructive ops impossible by construction. Starts as agentic DFIR; designed to expand toward agentic SOC and beyond.
β github.com/Juwon1405/agentic-dart Β· Submission to SANS FIND EVIL! 2026 Β· MIT
|
|
π§ͺ yushin-gendfir-rag
|
π GitNote
|
- Network Attack Packet Analysis for Security Practitioners Β· 보μ μ€λ¬΄μλ₯Ό μν λ€νΈμν¬ κ³΅κ²© ν¨ν· λΆμ (co-author, lead)
Freelec, 2019.11 Β· ISBN 9788965402589 Β· ~370 pp.
A practitioner's reference covering DDoS, web exploitation, malicious traffic, wireless intrusion, system exploitation, and large-volume packet analysis.
β Yes24 Β· Aladin Β· Kyobo Β· Google Books
- π₯ Gold Prize, 2017 Korea Open-Source Software Developer Contest (NIPA, national OSS award)
- π Patent (filed): Security Event Correlation Analysis Apparatus (2018, Netmarble Corp.)
- π― 4th place, 2017 CCE National Cyber Defense Competition (National Intelligence Service of Korea)
- π Special Prize, 2015 LINE Bug Bounty Program (LINE Corp.)
- YouTube: DoubleS1405 β long-running Korean-language information-security lecture channel (2014βpresent)
- Awesome Stars (GitNote) β β 204 starred repos categorized into 12 buckets (DFIR / Blue Team / AI / Red Team / Malware / OSINT / etc.), regenerated periodically.
- DFIR β Digital Forensics & Incident Response
- BlueTeam β Defensive operations & SOC
- Tools & Tips β Analysis utilities
- DevSecOps β Security automation & AI
- Gist β Code snippets
Research collaboration Β· CTF Β· CSIRT exchange Β· Open-source security tooling


