CirriusTech
  • Home
  • Tech
  • Projects
  • Personal
  • Fiction
  • About
  • Certifications
β˜• Enjoying the content? Consider supporting me on Ko-fi

Projects & Research

Tools, Research & Open Source

Security research, open source tooling, and experimental projects. Built to explore, understand, and solve real problems.

πŸ”¬

OID-See

BloodHound for OAuth in Entra ID β€” maps third-party app consent, scopes, assignments, and trust signals into a graph to surface impersonation risk and OAuth sprawl.

GitHub
πŸ”¬

ISDF β€” Intune Stateful Device Fingerprinting

Cloud-stamped device metadata for Conditional Access β€” moves device trust out of the endpoint and into Azure, using TPM-rooted hardware identifiers validated by a Logic App with Managed Identity.

GitHub
πŸ”¬

KuShu β€” Attack & Defence Research

KuShuSec is a collection of cloud security attack and defence research, tools, and mind maps β€” including the KuShu-Atama attack/defence mind map repository and SPADE research.

GitHub
πŸ”¬

Az-Skywalker

A collection of Azure security research tools exposing control plane isolation flaws, cross-plane data exposure, and silent data harvesting in Microsoft Azure iPaaS services.

GitHub
πŸ”¬

The Audrey Project

A curated RSS/OPML feed collection for tech and security professionals β€” helping you stay current without drowning in noise.

GitHub
Recent Posts
Synthetic Authority and Constrained Probabilism: What Overloaded Minds Teach Us About AI
Synthetic Authority and …

Hero image generated by ChatGPT

This is a personal blog. All opinions are my own and not those of my employer.


We Are Not Exploring New Territory

After publishing Capability β‰  Obligation, I had a conversation that lingered far longer than I expected.

It wasn’t with a policymaker, a …

February 15, 2026 Read
MCP, Latency, and Constrained Probabilism
MCP, Latency, and …

The Wrong Latency Question

When people talk about latency in AI systems, they usually mean network latency …

February 7, 2026 Read
Capability β‰  Obligation: When Agentic Systems Start Hiring Humans
Capability β‰  Obligation: …

Hero image generated by ChatGPT

This is a personal blog. All opinions are my own and not those of my employer.


Capability β‰  Obligation

There is a phrase I keep coming back to as I watch the current wave of agentic systems spill out of demo videos and into the real world:

Capability β‰  …

February 5, 2026 Read
From Clawdbot to GAINet: When Agent Experiments Outrun Accountability
From Clawdbot to GAINet: …

Hero image generated by ChatGPT

This is a personal blog. All opinions are my own and not those of my employer.


From Clawdbot to GAINet: When Agent Experiments Outrun Accountability

This post didn’t start as a philosophical musing about AI.

It started with a very practical, very familiar …

January 31, 2026 Read
Allowing ARM for Dev Box: When Portals Impersonate Users (and How to Avoid It)
Allowing ARM for Dev Box: …

Hero image generated by ChatGPT This is a personal blog and all content herein is my own opinion and not that of my employer.


What The Entra Fudge?!

There’s a particular flavour of frustration that only appears when:

  • you follow the documentation,
  • you apply least privilege,
  • you design sensible …

January 20, 2026 Read
OID-See v1.0.1: Small Release, Sharper Edges
OID-See v1.0.1: Small …

OID-See v1.0.1 is out πŸŽ‰

This is a precision release.

No shiny new dashboards.
No dramatic architectural upheaval.
Just tighter logic, fewer false positives, and a scoring model that better reflects how Entra actually behaves in the real world.

If you’re already using OID-See, this release should …

January 18, 2026 Read
Footer logo
© 2026 All Rights Reserved