Root//Drifter
Not technical? Start here →
Security knowledge is a right, not a product. rootdrifter is building in public to prove it.
About
rootdrifter is the working handle of a security professional building toward cleared entry-level roles in the UK, Netherlands, and Germany.
The approach is to build and to break with the same discipline, and to document both to a standard a reviewer can audit. That has produced a hardened Linux workstation and a compartmentalised mobile platform, a grey-box penetration test mapped to recognised benchmarks, and dissertation-level research into whether language models can reason causally about social engineering rather than just pattern-match it. Current focus: CompTIA Security+, active CTF practice, and a Wazuh SIEM home lab for hands-on detection engineering.
Academic background: a First Class BSc in Computer Networks & Cyber Security. This site stays pseudonymous by design — a named CV with full academic and contact detail is available on request.
Portfolio
Hardened Fedora workstation — LUKS2 full-disk encryption unlocked by a FIDO2 hardware key, remote pre-boot SSH unlock, and all DNS filtered before it leaves the host.
3-keyslot LUKS2 · Nitrokey 3A NFC · WireGuard egress spectre · offensiveGrey-box pentest of an Apache 2.4.58 host from a CIS-L1 PostgreSQL server — PTES, findings mapped to CWE / CIS / ISO 27002, SHA-256 evidence chain.
7 findings · primary CWE-548 · SHA-256 chain mirage · researchCausal LLM evaluation over an 88,647-email phishing corpus — can frontier models reason about social engineering, or only pattern-match it?
88,647 emails · ICC 0.98 · GPT-4 94.2% DAGFull portfolio → all six projects
Latest writing
Most SOCs do not have a detection problem — they have a signal-to-noise problem. Why the tuning loop, not the rule count, decides what gets caught.
Read →A relocked bootloader, a hardware root of trust, and a boot chain you can independently verify — how verified boot actually works and why the discrete secure element matters.
Read →Auditability, failure behaviour, and cryptokey routing: the comparison that matters in practice, grounded in running full-tunnel WireGuard on real infrastructure.
Read →More transmissions incoming · Subscribe for early access
Active work
Contact
[email protected] · github.com/rootdrifter
Open to cleared security roles in the UK, Netherlands, and Germany. CV available on request.