I help Fortune 500 companies build Autonomous Security Programs and AI Red Teams. 20+ years in offensive and defensive security — from hands-on red team ops to vCISO engagements across regulated industries.
My GitHub is where I document the work: AI attack tooling, red team playbooks, cloud pentest methodology, and bug bounty systems. If it's offensive, automated, or AI-native, it's probably here.
🔭 Currently working on AI-native security orchestration — autonomous red-team & OSINT-graph workflows (Claude Code + MCP servers like Shodan, Metasploit, Nuclei + Flowsint for visual entity investigations) that find and validate vulnerabilities at scale
👯 Looking to collaborate with AI security researchers, bug bounty hunters, red teamers, and anyone building on top of agentic AI for offensive security
🤝 Looking for help with Go tooling for recon automation, my first zero day, CVE and custom nuclei template development
🌱 Currently learning agentic AI attack surfaces, LLM jailbreak chains, and adversarial ML — alongside AI/ML coursework at MIT Sloan
💬 Ask me about AI red teaming, bug bounty methodology, AWS privilege escalation, vCISO program builds, or how to run a white-box pentest at scale for under $2k
📫 Reach me at sentinelsec.ai or @aladdinelston on Twitter
⚡ Fun fact: I recently ran 100 AI-powered white-box pentests across repos and found 4000 Critical/High vulnerabilities — including RCE, cross-tenant IDOR exposing bank PII, and committed AWS keys in production. A traditional firm would have billed $2M for the same scope.
| Project | What it is |
|---|---|
| Shannon | Autonomous white-box AI pentester — analyzes source, executes real exploits |
| HexStrike-AI | MCP server giving AI agents 150+ offensive-security tools |
| Flowsint | Visual graph-based OSINT investigation platform |
| Personal AI Infrastructure | Agentic AI infra for magnifying human capability |
| SecondBrain | Research OS — DeepScientist + Obsidian synthesis |
| AI-Redteaming | Curated LLM/AI attack tooling — prompt injection, jailbreaks, agentic threats |
| jsleaks | Zero-dependency scanner for API keys & secrets in JS |