CirriusTech
  • Home
  • Tech
  • Projects
  • Personal
  • Fiction
  • About
  • Certifications
β˜• Enjoying the content? Consider supporting me on Ko-fi

Projects & Research

Tools, Research & Open Source

Security research, open source tooling, and experimental projects. Built to explore, understand, and solve real problems.

πŸ”¬

a-scanner-duskli

Automated accessibility scanning for dusk.li, focused on dark mode support and WCAG2AA color contrast.

GitHub
πŸ”¬

OID-See

BloodHound for OAuth in Entra ID β€” maps third-party app consent, scopes, assignments, and trust signals into a graph to surface impersonation risk and OAuth sprawl.

GitHub
πŸ”¬

ISDF β€” Intune Stateful Device Fingerprinting

Cloud-stamped device metadata for Conditional Access β€” moves device trust out of the endpoint and into Azure, using TPM-rooted hardware identifiers validated by a Logic App with Managed Identity.

GitHub
πŸ”¬

KuShu β€” Attack & Defence Research

KuShuSec is a collection of cloud security attack and defence research, tools, and mind maps β€” including the KuShu-Atama attack/defence mind map repository and SPADE research.

GitHub
πŸ”¬

Az-Skywalker

A collection of Azure security research tools exposing control plane isolation flaws, cross-plane data exposure, and silent data harvesting in Microsoft Azure iPaaS services.

GitHub
πŸ”¬

The Audrey Project

A curated RSS/OPML feed collection for tech and security professionals β€” helping you stay current without drowning in noise.

GitHub
  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • »
  • »»
Recent Posts
Continuous Access Evaluation: Is it really tho?
Continuous Access …

This is a personal blog and all content herein is my own opinion and not that of my employer. Background Continuous Access Evaluation, or CAE, is one of those security controls with a wonderfully descriptive name. Access is not supposed to be evaluated only when you first authenticate. It is …

September 16, 2026 Read
Daddy Issues: When APIM Workspaces Inherit the Parent Identity
Daddy Issues: When APIM …

This is a personal blog and all content herein is my own opinion and not that of my employer. Introduction Sometimes security research starts with an exploit. Sometimes it starts with a much more boring question: “Where is the actual security boundary?” This one started with the latter. …

September 14, 2026 Read
What The Entra Fudge?! Tenant Restrictions v1 Doesn't Mean What You Think It Means
What The Entra Fudge?! …

If you implemented Tenant Restrictions v1 and only validated Restrict-Access-To-Tenants, you may only have implemented half the control you think you have.

August 19, 2026 Read
We Automated Dave: Security Debt at Machine Speed
We Automated Dave: …

This is a personal blog. All opinions are my own - not my employer’s. There’s apparently a new category of security incident called AI escape. Except there isn’t. That phrase might be useful shorthand for headlines, and some of the incidents behind it are genuinely serious, but I think …

August 8, 2026 Read
Prompting Was Never the Control Plane
Prompting Was Never the …

This is a personal blog. All opinions are my own - not my employer’s. At some point over the last few months, I accidentally built a control plane for coding agents. This was not the plan. The plan, to the extent that there was one, was much smaller and much more normal. I wanted coding agents to …

July 1, 2026 Read
 Beyond The Door #1: The Illusion Of The Locked Door
Beyond The Door #1: The …

We keep acting like doors are portals into trust and expected good behaviour. That was never true, but has never been more dangerous an assumption than it is now.

June 14, 2026 Read
Footer logo
© 2026 All Rights Reserved