Skip to content
View adulau's full-sized avatar
👨‍💻
Doing stuff
👨‍💻
Doing stuff

Sponsoring

@xwmx
@cmars
@dmachard
@jgm
@sudo-project

Block or report adulau

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
adulau/README.md

Alexandre Dulaunoy — adulau

I break stuff and I do stuff. I enjoy people using machines in unexpected ways, and turning that curiosity into free software, open data, and open specifications.

My work spans incident response, threat intelligence, vulnerability research, digital forensics, and information representation. At CIRCL, and with communities beyond it, I help build tools that analysts can inspect, run, adapt, and share.

Website & writing · Mastodon · Research / ORCID · Photography

Open source over the years

A conceptual sketch of curiosity, building, investigating, sharing, and open standards as overlapping threads flowing from earlier to now.

Keeping track of everything I have started, maintained, or contributed to is nearly impossible. This is a selection, built with many other people:

  • Early tools and experiments: hotp-js, a JavaScript HOTP implementation dating back to 2009; Forban, for opportunistic file sharing on local networks without Internet access; and passive DNS and certificate-monitoring tools.
  • Long-running collaborative projects: cve-search, with contributions going back to 2012; AIL, since 2014; and the MISP ecosystem, including the taxonomy work we began in 2015. These connect software, shared knowledge, and operational security communities.
  • More recent work: hashlookup, RansomLook, and Vulnerability-Lookup, alongside new experiments in analysis, open source sustainability, and radio communication.

Threat intelligence and collaborative analysis

I am part of the MISP core team and contribute across its software, data models, documentation, and open specifications. I also work with the AIL Project, D4 Project, and CIRCL communities.

I have worked on misp-modules for years and continue to maintain it. It has become key tooling for MISP and other CTI tools. I also started a small MISP hackathon several years ago.

Project What it helps people do
MISP Collect, correlate, and share threat intelligence across organisations.
MISP taxonomies, galaxies, objects, and warning lists Give intelligence shared vocabularies, context, structured representations, and checks against misleading indicators.
misp-modules Provide reusable enrichment, import, export, and workflow actions for MISP and other CTI tools, through an independent API and standalone interfaces.
AIL Collect and analyse unstructured information, track leaks and threats, and support investigations.
Tempolocus Infer likely timezones and locations from activity patterns over time, supporting analysis in AIL.
D4 Build distributed sensor networks for collecting and analysing security telemetry.
RansomLook Track ransomware groups and their public activity, including leak-site publications.
Threat Actor Explorer Explore the MISP galaxy threat-actor dataset locally in a browser.
Fanything Explore network fingerprinting for correlation and CTI pivoting. The project and its fingerprint format are in an early, experimental phase.

Vulnerabilities and disclosure

I co-develop and co-maintain tools that make vulnerability information easier to find, correlate, and use, working with the cve-search and Vulnerability-Lookup communities.

Project Focus
cve-search Aggregate vulnerability sources and support local searches for CVEs and affected products.
Vulnerability-Lookup Correlate vulnerability advisories, share sightings and comments, and support coordinated disclosure and advisory publication.
git-vuln-finder Find potential vulnerability fixes from Git commit messages.
cpe-guesser Guess CPE identifiers from common software names.

An earlier experiment, SHVI allocator, explored community allocation of software and hardware vulnerability identifiers. It remains part of the history of this work rather than a promise of a maintained service.

Digital forensics and Internet infrastructure

These are tools I initially developed or maintain, from identifying known files to understanding domains, IP addresses, and encrypted network traffic.

Project Focus
hashlookup-server Fast hash lookups against large reference datasets, used in the CIRCL hashlookup service.
hashlookup-forensic-analyser Compare files in a forensic target with hashlookup and report known and unknown files.
hashlookup-lib and hashlookup-nsrl Import hash records and NIST NSRL datasets into hashlookup.
DomainClassifier Extract and classify domains, hostnames, and IP addresses from unstructured text.
mmdb-server Serve geographic and autonomous-system lookups from MaxMind-format databases, including the GeoOpen dataset.
ptrclassify Infer likely IP usage and location from reverse-DNS hostnames.
ssldump Analyse SSL/TLS traffic, with modern maintenance, JSON output, fingerprinting, and IPv6 support.
netbeacon Check the accuracy and visibility of network capture and monitoring systems.

Earlier work includes pdns-qof-server, pdns-toolkit, and crl-monitor, exploring passive DNS and the history of certificates and Internet infrastructure.

Open standards

Working implementations and open specifications belong together. I work on standards that make security information easier to publish, exchange, and use across independent tools and communities. My standards work also includes participation in the OASIS Cyber Threat Intelligence (CTI) Technical Committee.

GCVE — open vulnerability standards and practices

I contribute to the GCVE initiative, the Global CVE Allocation System, developing specifications and Best Current Practices for a decentralised vulnerability ecosystem. This work connects identifier allocation, vulnerability publication, operational guidance, and interoperable data models with implementations such as Vulnerability-Lookup.

The GCVE BCP collection includes published documents and drafts under public review. Areas of this work include:

The specifications evolve through an open development and review process, with community feedback and implementation experience informing revisions.

MISP standards

Through misp-standard.org, I help develop, maintain, and publish free and open standards for collaborative intelligence. This includes the MISP core, taxonomy, galaxy, and object template formats, connecting shared data models with working implementations across the threat intelligence ecosystem. The standards website and publication sources complement the MISP specification sources and their Internet-Drafts.

IETF Internet-Drafts

I author or co-author Internet-Drafts to document formats, make independent implementations possible, and improve interoperability. The documents below are Internet-Drafts; their current status and revisions are available in the IETF Datatracker.

Specification Purpose
MISP core format, taxonomy format, galaxy format, and object template format Describe interoperable threat intelligence and its classification, context, and structure. Sources and implementation context.
Passive DNS — Common Output Format Give passive DNS services a common representation for their results.
hashlookup format Describe the exchange of hashlookup records and associated metadata.
Programming Methodology Framework Document a practical approach to software engineering. Source.
Open Contributions Descriptor Publish machine-readable information about an organisation's contributions to open source, open data, and open standards.
Radio Image Framing Protocol Explore image transmission over low-rate radio links, alongside the experimental RIFP implementation.

Writing, teaching, and keeping things alive

Open source work also means documenting techniques, sharing research, teaching, and maintaining software after the initial excitement has passed.

  • The Art of Pivoting is my open book on finding relationships in intelligence investigations, using reproducible techniques and tools such as MISP and AIL.
  • threat-intelligence.eu collects open standards, documents, methodologies, and processes for threat intelligence.
  • OSSTRL explores how repository evidence can help assess open source software readiness.
  • I write about security research, software, and open data on foo.be, lecture on information security, and help organise hack.lu.
  • I keep useful tools alive, including ssldump, and build small utilities such as rss-tools. Maintenance is part of the work, even when it is less visible than a new project.

For the wider picture, browse my repositories and the organisations linked above. Issues, patches, improved documentation, and new ideas are welcome in the relevant projects.

Pinned Loading

  1. ssldump ssldump Public

    ssldump - (de-facto repository gathering patches around the cyberspace)

    C 258 91

  2. hashlookup-server hashlookup-server Public

    Fast lookup server for NSRL and other hash database used in digital forensic

    Python 52 8

  3. DomainClassifier DomainClassifier Public

    DomainClassifier is a Python (2/3) library to extract and classify Internet domains/hostnames/IP addresses from raw unstructured text files following their DNS existence, localization or attributes.

    Python 84 10

  4. git-vuln-finder git-vuln-finder Public

    Forked from cve-search/git-vuln-finder

    Finding potential software vulnerabilities from git commit messages

    Python 5 2

  5. mmdb-server mmdb-server Public

    mmdb-server is an open source fast API server to lookup IP addresses for their geographic location.

    Python 205 26

  6. RansomLook/RansomLook RansomLook/RansomLook Public

    Yet another Ransomware gang tracker

    Python 674 117