Skip to content
View icedracon's full-sized avatar

Block or report icedracon

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
icedracon/README.md

ICEDRACON — cybersecurity, investigation, and open-source engineering. A short orbital animation plays once; all text stays still.

Static banner

ADhammer website ↗   ·   Repositories   ·   Rust SDK

Security work. Explainable results.

I'm icedracon, a cybersecurity specialist and open-source developer. My focus spans SOC and incident response, malware analysis, and authorized Active Directory, web, and Android / APK pentesting.

I build mostly in Rust, with a particular interest in Windows identity, protocol engineering, and evidence that another person can inspect.

01 / Security practice

Focus What matters to me
SOC & incident response SIEM investigations, log and traffic analysis, EDR / DLP context, and clear incident handoffs.
Malware & detection Understanding behavior, documenting findings, and working with Sigma and YARA detection concepts.
Active Directory pentesting Identity relationships, directory posture, privilege paths, and evidence-backed conclusions within authorized scope.
Web & Android / APK pentesting Scoped application assessment, static and dynamic analysis, and actionable reporting.

These are my practice areas—not a claim that every project below implements them.

02 / Featured work

ADhammer

Active Directory assessment, built around evidence.

An open-source Rust CLI for directory assessment, Tier-0 path analysis, and structured reporting. A possible path is not proof: capability support and outstanding validation are recorded in the validation ledger.

Explore the experience ↗ · Read the source · Releases · crates.io

Protocols & Windows foundations

Small building blocks for larger systems. Each project has its own scope, documentation, and validation status.

Area Selected repositories
Identity & cryptography kerbcore · ntlmssp · dpapi-ng
Transport & representation smb2-client · dcerpc · ms-ndr
Windows evidence & access windows-eventlog-native · windows-sddl · ad-access
Native interfaces win32-min

A different side: ECHO

A pixel-art desktop companion and a place to explore product design, animation, and local-first software. Meet ECHO ↗

03 / How I work

Scope before action. Explicit authorization and clear boundaries.

Evidence before conclusions. Observation, inference, and proof stay distinct.

Clarity before noise. Focused tools, readable reports, and reusable components.


CYBERSECURITY   /   OPEN SOURCE   /   BUILT WITH INTENT

Pinned Loading

  1. adhammer adhammer Public

    Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported validation, and evidence reporting.

    Rust 101 6