I break stuff and I do stuff. I enjoy people using machines in unexpected ways, and turning that curiosity into free software, open data, and open specifications.
My work spans incident response, threat intelligence, vulnerability research, digital forensics, and information representation. At CIRCL, and with communities beyond it, I help build tools that analysts can inspect, run, adapt, and share.
Website & writing · Mastodon · Research / ORCID · Photography
Keeping track of everything I have started, maintained, or contributed to is nearly impossible. This is a selection, built with many other people:
- Early tools and experiments: hotp-js, a JavaScript HOTP implementation dating back to 2009; Forban, for opportunistic file sharing on local networks without Internet access; and passive DNS and certificate-monitoring tools.
- Long-running collaborative projects: cve-search, with contributions going back to 2012; AIL, since 2014; and the MISP ecosystem, including the taxonomy work we began in 2015. These connect software, shared knowledge, and operational security communities.
- More recent work: hashlookup, RansomLook, and Vulnerability-Lookup, alongside new experiments in analysis, open source sustainability, and radio communication.
I am part of the MISP core team and contribute across its software, data models, documentation, and open specifications. I also work with the AIL Project, D4 Project, and CIRCL communities.
I have worked on misp-modules for years and continue to maintain it. It has become key tooling for MISP and other CTI tools. I also started a small MISP hackathon several years ago.
| Project | What it helps people do |
|---|---|
| MISP | Collect, correlate, and share threat intelligence across organisations. |
| MISP taxonomies, galaxies, objects, and warning lists | Give intelligence shared vocabularies, context, structured representations, and checks against misleading indicators. |
| misp-modules | Provide reusable enrichment, import, export, and workflow actions for MISP and other CTI tools, through an independent API and standalone interfaces. |
| AIL | Collect and analyse unstructured information, track leaks and threats, and support investigations. |
| Tempolocus | Infer likely timezones and locations from activity patterns over time, supporting analysis in AIL. |
| D4 | Build distributed sensor networks for collecting and analysing security telemetry. |
| RansomLook | Track ransomware groups and their public activity, including leak-site publications. |
| Threat Actor Explorer | Explore the MISP galaxy threat-actor dataset locally in a browser. |
| Fanything | Explore network fingerprinting for correlation and CTI pivoting. The project and its fingerprint format are in an early, experimental phase. |
I co-develop and co-maintain tools that make vulnerability information easier to find, correlate, and use, working with the cve-search and Vulnerability-Lookup communities.
| Project | Focus |
|---|---|
| cve-search | Aggregate vulnerability sources and support local searches for CVEs and affected products. |
| Vulnerability-Lookup | Correlate vulnerability advisories, share sightings and comments, and support coordinated disclosure and advisory publication. |
| git-vuln-finder | Find potential vulnerability fixes from Git commit messages. |
| cpe-guesser | Guess CPE identifiers from common software names. |
An earlier experiment, SHVI allocator, explored community allocation of software and hardware vulnerability identifiers. It remains part of the history of this work rather than a promise of a maintained service.
These are tools I initially developed or maintain, from identifying known files to understanding domains, IP addresses, and encrypted network traffic.
| Project | Focus |
|---|---|
| hashlookup-server | Fast hash lookups against large reference datasets, used in the CIRCL hashlookup service. |
| hashlookup-forensic-analyser | Compare files in a forensic target with hashlookup and report known and unknown files. |
| hashlookup-lib and hashlookup-nsrl | Import hash records and NIST NSRL datasets into hashlookup. |
| DomainClassifier | Extract and classify domains, hostnames, and IP addresses from unstructured text. |
| mmdb-server | Serve geographic and autonomous-system lookups from MaxMind-format databases, including the GeoOpen dataset. |
| ptrclassify | Infer likely IP usage and location from reverse-DNS hostnames. |
| ssldump | Analyse SSL/TLS traffic, with modern maintenance, JSON output, fingerprinting, and IPv6 support. |
| netbeacon | Check the accuracy and visibility of network capture and monitoring systems. |
Earlier work includes pdns-qof-server, pdns-toolkit, and crl-monitor, exploring passive DNS and the history of certificates and Internet infrastructure.
Working implementations and open specifications belong together. I work on standards that make security information easier to publish, exchange, and use across independent tools and communities. My standards work also includes participation in the OASIS Cyber Threat Intelligence (CTI) Technical Committee.
I contribute to the GCVE initiative, the Global CVE Allocation System, developing specifications and Best Current Practices for a decentralised vulnerability ecosystem. This work connects identifier allocation, vulnerability publication, operational guidance, and interoperable data models with implementations such as Vulnerability-Lookup.
The GCVE BCP collection includes published documents and drafts under public review. Areas of this work include:
- Trusted directories and distributed publication: directory signature verification (BCP-01) and decentralised publication (BCP-03).
- Disclosure, allocation, and governance: vulnerability handling and disclosure (BCP-02), identifier allocation (BCP-04), numbering authority requirements (BCP-06), record scope (BCP-09), and the vulnerability assigner scorecard (BCP-13).
- Vulnerability records and provenance: the GCVE vulnerability format (BCP-05) and extensions for AI-assisted annotations, patch-to-vulnerability generation provenance, and handling and disclosure timelines.
- Exploitation evidence and observations: KEV assertions and NKEV assessments (BCP-07) and the vulnerability sighting format (BCP-12).
- Affected products: improved Common Platform Enumeration (BCP-10).
The specifications evolve through an open development and review process, with community feedback and implementation experience informing revisions.
Through misp-standard.org, I help develop, maintain, and publish free and open standards for collaborative intelligence. This includes the MISP core, taxonomy, galaxy, and object template formats, connecting shared data models with working implementations across the threat intelligence ecosystem. The standards website and publication sources complement the MISP specification sources and their Internet-Drafts.
I author or co-author Internet-Drafts to document formats, make independent implementations possible, and improve interoperability. The documents below are Internet-Drafts; their current status and revisions are available in the IETF Datatracker.
| Specification | Purpose |
|---|---|
| MISP core format, taxonomy format, galaxy format, and object template format | Describe interoperable threat intelligence and its classification, context, and structure. Sources and implementation context. |
| Passive DNS — Common Output Format | Give passive DNS services a common representation for their results. |
| hashlookup format | Describe the exchange of hashlookup records and associated metadata. |
| Programming Methodology Framework | Document a practical approach to software engineering. Source. |
| Open Contributions Descriptor | Publish machine-readable information about an organisation's contributions to open source, open data, and open standards. |
| Radio Image Framing Protocol | Explore image transmission over low-rate radio links, alongside the experimental RIFP implementation. |
Open source work also means documenting techniques, sharing research, teaching, and maintaining software after the initial excitement has passed.
- The Art of Pivoting is my open book on finding relationships in intelligence investigations, using reproducible techniques and tools such as MISP and AIL.
- threat-intelligence.eu collects open standards, documents, methodologies, and processes for threat intelligence.
- OSSTRL explores how repository evidence can help assess open source software readiness.
- I write about security research, software, and open data on foo.be, lecture on information security, and help organise hack.lu.
- I keep useful tools alive, including ssldump, and build small utilities such as rss-tools. Maintenance is part of the work, even when it is less visible than a new project.
For the wider picture, browse my repositories and the organisations linked above. Issues, patches, improved documentation, and new ideas are welcome in the relevant projects.






