Security engineer who writes the tools I need and open-sources them when they might help someone else. Mostly Go, C, and Python.
CLIs that turn live SIEM and EDR platforms into code you can git diff — each with a built-in MCP server, every mutation dry-run until --yes:
splunkctl— Splunk Enterprise SIEM + Splunk SOAR as codes1ctl— SentinelOne Singularity Platform as codesecopsctl— Google SecOps (Chronicle SIEM + Siemplify SOAR) as code
Evidence-only RAG + MCP servers for banking & fintech regulation — exact provisions from official government sources, never paraphrased. Six ASEAN jurisdictions, free, no signup:
banhmi 🇻🇳 · laksa 🇲🇾 · rendang 🇮🇩 · kaya 🇸🇬 · tomyum 🇹🇭 · amok 🇰🇭
compliary— evidence-only corpus + MCP server for the control frameworks auditors ask about (ISO/IEC 27001 family, NIST CSF & 800-53, PCI DSS, SOC 2, CIS, SWIFT CSCF, CSA CCM, COBIT) — self-deployed, no licensed text in the repo
go get-able straight off danny.vn/…: s1 · secops · fortigate · fortimgr · nessus · vngcloud · gnode · kaggle
offthebook— memory-only Windows PE execution, SMB-over-QUIC SEC_IMAGE loading, PIC shellcode in pure Csplunk-sdk-python— Splunk SDK for Pythononnxruntime/go— Go bindings for ONNX Runtime C API (open PR)flowcvcli— drive a FlowCV résumé from the CLI or Python
More at danny.vn.


