Skip to content
View liamkirton's full-sized avatar
๐Ÿ 
Working from home
๐Ÿ 
Working from home

Highlights

  • Pro

Block or report liamkirton

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
liamkirton/README.md

Hey ๐Ÿ‘‹, I'm Liam GitHub LinkedIn Twitter Web

I'm currently a Principal Security Researcher at Microsoft Security Research (MSecR), where I work on R&D related to Threat Intelligence and Detection for Microsoft Defender for Endpoint (EDR) and Windows Defender Antivirus.

I write a lot of Python ๐Ÿ with Pandas ๐Ÿผ in Jupyter Notebooks ๐Ÿš€ to mine interesting security events from trillions of daily signals held in Kusto โ˜๏ธ๐ŸŒŠ.

Here are some recent spare-time projects:

I spent 15 years working on Vulnerability Research and Windows Internals, and here are some ancient obsolete Windows security tools:

Popular repositories Loading

  1. lsppyfilter lsppyfilter Public

    [2007] Windows tool, offers the ability to dynamically and transparently modify incoming and outgoing network traffic, as well as to redirect outgoing connection requests. Uses a Windows Layered Seโ€ฆ

    C++ 10 9

  2. sslcat sslcat Public

    [2008] Windows netcat for SSL

    C++ 6 5

  3. ieswitchssl ieswitchssl Public

    [2008] IE toolbar allowing configuration of SSL protocols/parameters

    C++ 5 4

  4. ndisarpfilter ndisarpfilter Public

    [2007] Windows NDIS firewall that processes all incoming and outgoing network packets through a list of configured MAC address filters

    C 4 4

  5. sslpyfilter sslpyfilter Public

    [2008] Capture and modify cleartext traffic before encryption/after decryption by Windows SSL SSPI API

    C++ 4 4

  6. ippyproxy ippyproxy Public

    [2008] IpPyProxy redirects traffic received on a local listening port to a specified target ip:port, filtering any received data through a dynamically loaded Python script

    C++ 4 4