Cybersecurity
Research Lab
Ahmed Awad (NullC0d3) — Advancing the science of behavioral digital attribution, AI-powered vulnerability assessment, and cybersecurity automation through open-source innovation.
Research Impact
Metrics reflecting a career in cybersecurity research and open-source development
Areas of Research
Advancing the intersection of behavioral science, artificial intelligence, and cybersecurity.
Behavioral Digital Attribution
Formal methodology for attributing digital artifacts to human sources through behavioral analysis.
Cyber Threat Intelligence
Advanced threat actor profiling, campaign attribution, and intelligence-driven operations.
Digital Identity & Behavioral Biometrics
Cognitive Centroid theory — a formal model of behavioral identity as an asymptotic attractor in feature space.
Identity Intelligence (IdINT)
Systematic identity resolution across disparate data sources and platforms.
OSINT & Digital Forensics
Advanced open-source intelligence collection, digital footprint analysis, and identity correlation.
AI for Cybersecurity
Application of artificial intelligence and machine learning to threat attribution and behavioral analysis.
Research Ecosystem
An integrated ecosystem of open-source cybersecurity research platforms — from behavioral attribution science to offensive security intelligence to environment automation.
AnubisX Framework
Behavioral Digital Attribution
Scientific foundation — formal methodology for attributing anonymous digital identities through behavioral analysis.
HunterX
Attack Surface Intelligence
Intelligence layer — AI-assisted vulnerability assessment, knowledge graph, and security skills framework.
RabbitHole
Security Automation
Infrastructure layer — rapid provisioning of combat-ready cybersecurity environments with supply chain security.
Featured Projects
Flagship open-source cybersecurity research platforms.
AnubisX Framework
Behavioral Digital Attribution Framework
A formal framework for behavioral digital attribution comprising 16 axioms, Cognitive Centroid theory, 292 defined objects, 37 algorithms across 5 behavioral modalities, and a 4-tier validation infrastructure with 31 pre-specified acceptance criteria.
Core Capabilities
- 16 Formally Specified Axioms
- Cognitive Centroid Theory
- 292 Mathematical Objects
- 37 Algorithms across 5 Modalities
- 4-Tier Validation Infrastructure
HunterX
AI-Assisted Vulnerability Hunter
HunterX is an open-source, AI-assisted offensive security platform and intelligent vulnerability assessment framework. Unlike traditional scanners that rely solely on payload execution or signature matching, HunterX follows a reasoning-driven workflow — Observe → Hypothesize → Probe → Verify — enabling context-aware security analysis, evidence-driven decision making, and intelligent vulnerability verification with explainable AI outputs.
Core Capabilities
- AI-Assisted Reasoning Engine (18 goal types)
- 41 Security Skills Framework
- 10 Specialized AI Agents
- Knowledge Graph for Attack Path Analysis
- Enterprise-Ready REST API (40+ endpoints)
RabbitHole
Universal Cybersecurity Environment Installer / Provisioning Framework
RabbitHole provisions combat-ready cybersecurity environments in minutes. Originally a single-file Bash installer, it has evolved into a modular, extensible Cybersecurity Environment Provisioning Framework with a plugin system, state management, rollback, supply-chain security, and full CLI tooling.
Core Capabilities
- Distro Agnostic Installation
- Plugin-Based YAML Architecture
- State Management & Snapshots
- Supply Chain Security (SHA256)
- Rollback & Resume Capability
Ecosystem Comparison
How the three platforms complement each other within the cybersecurity research ecosystem.
| Aspect | AnubisX Framework | HunterX | RabbitHole |
|---|---|---|---|
| Purpose | Scientific framework for behavioral digital attribution | AI-assisted offensive security assessment platform | Cybersecurity environment provisioning framework |
| Target Audience | Researchers, forensic analysts, attribution specialists | Penetration testers, red teamers, security engineers | Security practitioners, SOC teams, CTI analysts |
| Primary Function | Attribute anonymous digital identities through behavioral analysis | Automated vulnerability discovery and verification with AI reasoning | Provision combat-ready cybersecurity environments in minutes |
| Technologies | Python, Mathematical Modeling, Statistical Analysis | Python 3.11+, FastAPI, SQLite + FTS5, OpenAI, Ollama, Docker | Bash, YAML, Docker Compose, GitHub Actions, ShellCheck |
| Key Features | 16 axioms, 292 objects, 37 algorithms, 5 modalities, 4-tier validation | 41 skills, 10 agents, 18 goals, 40+ API endpoints, knowledge graph, payload intelligence | 7 operational roles, plugin architecture, state management, rollback, supply chain security |
| Outputs | Attribution decisions, confidence scores, evidence trails | Vulnerability reports (JSON/MD/SARIF/HTML), attack graphs, evidence packages | Installed environments, state snapshots, health reports |
| Real-world Use Cases | Forensic investigation, threat actor attribution, identity resolution | Bug bounty hunting, penetration testing, red team operations, CI/CD security | Lab deployment, team onboarding, CTI infrastructure, training environments |
| Ecosystem Role | Scientific foundation — provides behavioral attribution methodology | Intelligence layer — applies AI to attack surface discovery | Infrastructure layer — enables rapid environment provisioning |
Research Publications
Peer-reviewed articles and industry publications in cybersecurity and threat intelligence.
Inside the Mind of a Threat Actor: What CISOs Must Learn Before the Next Breach
Awad, A.
Cyber Defense Magazine
An exploration of threat actor psychology, decision-making processes, and cognitive patterns that security leaders must understand to anticipate and prevent sophisticated cyber attacks.
The Financialization of Cybercrime
Awad, A.
Cyber Defense Magazine
An analysis of the evolving financial infrastructure supporting cybercrime operations, including ransomware-as-a-service, cyber insurance arbitrage, and cryptocurrency-based money laundering.
Published Books
Five books exploring cybersecurity, threat intelligence, and the human dimensions of digital security.
You Can Hide Your Name... Not Your Mind
How Artificial Intelligence Reveals the Human Behind Digital Identities
Explores how artificial intelligence and behavioral analysis can unmask anonymous digital identities.
Inside the Hacker Hunter's Mind
A deep dive into the psychological and methodological approaches of those who track and apprehend cybercriminals.
Inside the Hacker Hunter's Toolkit
Comprehensive guide to the tools, techniques, and technologies used by cybersecurity professionals.
Inside the Hacker Hunter's Domain Cyber Intelligence
Examines the domain of cyber intelligence operations, from threat detection to attribution.
Inside the Hacker Hunter's AI Identity War
Investigates the emerging battlefield where artificial intelligence is used both to conceal and reveal digital identities.
Technical Expertise
Deep expertise demonstrated through research frameworks, open-source platforms, and published work.
AI & Machine Learning
Offensive Security
Threat Intelligence
OSINT & Forensics
Security Architecture
Development & DevOps
Cloud & Infrastructure
Research & Methodology
Open Source Portfolio
Comprehensive overview of research platforms and frameworks.
| Project | Category | Version | Status | Technologies | License | Links |
|---|---|---|---|---|---|---|
| AnubisX Framework | Research Framework | v3.0.0 | Active Research | PythonMathematical ModelingStatistical AnalysisLaTeX | CC BY 4.0 | |
| HunterX | Security Platform | v6.0.0 | Active Development | Python 3.11+FastAPISQLite + FTS5OpenAI API | Apache 2.0 | |
| RabbitHole | Provisioning Framework | v2.0.0 | Active Development | BashYAMLDocker ComposeGitHub Actions | Apache 2.0 |
Get in Touch
Research collaborations, speaking engagements, and professional inquiries are welcome.