Zero-Day Malware Behavior Predictor
Static behavioural analysis, MITRE ATT&CK mapping and an LLM reasoning layer — inferring intent without ever running the file.
- Python
- Django
- Next.js
- TypeScript
- MongoDB
- +3
GhostyyOnline
AI Security Systems Research
I build systems, break them on purpose, and go looking for the part that gave.
Most of my projects start as questions I couldn't leave alone — behavioural security, AI that has to run on my own hardware, and what data looks like when you stop storing it in rows.
One thesis project taking most of the time, and a set of questions running in the background behind it.
Behavioural anomaly detection that installs as Django middleware, learns what an application's normal traffic looks like, and flags the actors who stop matching it — shipped with the attack scenarios and benchmark harness used to prove it works.
Pipeline
Exploring
Each of these has a case study — what the problem was, what I actually built, and where it falls short.
Static behavioural analysis, MITRE ATT&CK mapping and an LLM reasoning layer — inferring intent without ever running the file.
Banking fraud modelled as structure rather than rows — laundering loops and shared-ownership rings surfaced in Neo4j.
A self-hosted workspace — notes, files, scraping and an assistant running on a local model rather than someone else's API.
Not interests — open engineering problems, each with something concrete that would settle it.
Grouped by what it's for rather than arranged as a wall of logos. Everything here appears in something I've shipped.
Python and TypeScript carry most of the weight; the rest show up where they have to.
React everywhere, Next.js when routing and rendering matter, Vite when they don't.
FastAPI for services, Django when the batteries are the point.
Chosen by the shape of the question — documents, graphs, columns or a single file.
Local models by default; scikit-learn where a classifier beats a language model.
Enough to run what I build without renting someone else's opinion about it.
This site is hosted from a GitHub repository, so it may as well read from one. Fetched in the browser — there is no server here to hide a token behind, and none is needed.
fetching…
BASIS-SDK
ML-based behavioral anomaly detection as Django security middleware, with a built-in dashboard.
2026-08-12
Python
Aim-Trainer
Browser-based aim training platform with a custom gameplay engine.
2026-06-12
TypeScript
FitAI
ML-powered fitness and health recommendation platform.
2026-04-17
JavaScript
Neural-Networks-Demo
Handwritten digit recognition with a CNN trained on MNIST.
2026-03-29
Python
Malware-Tracer
AI-powered zero-day malware behavior predictor.
2026-02-10
TypeScript
17 smaller things — a CNN behind a drawing canvas, an API scratchpad, Minecraft mods that taught me more about architecture than any course did, and a bot that fishes.
Open the labOpen to conversations about AI systems, security engineering, and problems that don't have a tidy answer yet. No form — a form would need a server, and this site doesn't have one.