ADhammer website ↗ · Repositories · Rust SDK
I'm icedracon, a cybersecurity specialist and open-source developer. My focus spans SOC and incident response, malware analysis, and authorized Active Directory, web, and Android / APK pentesting.
I build mostly in Rust, with a particular interest in Windows identity, protocol engineering, and evidence that another person can inspect.
| Focus | What matters to me |
|---|---|
| SOC & incident response | SIEM investigations, log and traffic analysis, EDR / DLP context, and clear incident handoffs. |
| Malware & detection | Understanding behavior, documenting findings, and working with Sigma and YARA detection concepts. |
| Active Directory pentesting | Identity relationships, directory posture, privilege paths, and evidence-backed conclusions within authorized scope. |
| Web & Android / APK pentesting | Scoped application assessment, static and dynamic analysis, and actionable reporting. |
These are my practice areas—not a claim that every project below implements them.
Active Directory assessment, built around evidence.
An open-source Rust CLI for directory assessment, Tier-0 path analysis, and structured reporting. A possible path is not proof: capability support and outstanding validation are recorded in the validation ledger.
Explore the experience ↗ · Read the source · Releases · crates.io
Small building blocks for larger systems. Each project has its own scope, documentation, and validation status.
| Area | Selected repositories |
|---|---|
| Identity & cryptography | kerbcore · ntlmssp · dpapi-ng |
| Transport & representation | smb2-client · dcerpc · ms-ndr |
| Windows evidence & access | windows-eventlog-native · windows-sddl · ad-access |
| Native interfaces | win32-min |
A pixel-art desktop companion and a place to explore product design, animation, and local-first software. Meet ECHO ↗
Scope before action. Explicit authorization and clear boundaries.
Evidence before conclusions. Observation, inference, and proof stay distinct.
Clarity before noise. Focused tools, readable reports, and reusable components.
CYBERSECURITY / OPEN SOURCE / BUILT WITH INTENT


