Skip to content
View icedracon's full-sized avatar

Block or report icedracon

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
icedracon/README.md

ICEDRACON — cybersecurity specialist and Rust engineer. Understand the system. Make the evidence clear.

ADhammer website Repositories crates.io Rust SDK docs

01 Profile

I'm icedracon, a cybersecurity specialist and open-source developer. I work across SOC and incident response, malware analysis, and authorized security assessment (Active Directory, web, and Android).

I build mostly in Rust. I'm especially interested in Windows identity, protocol engineering, and producing evidence that someone else can check.

$\color{#e5383b}{\textsf{SOC / IR}} \quad \color{#f77f00}{\textsf{Malware}} \quad \color{#14b8a6}{\textsf{Identity}} \quad \color{#8b5cf6}{\textsf{AppSec}} \quad \color{#3b82f6}{\textsf{Rust}}$

02 Core competencies

SOC and incident response: SIEM investigations, log and traffic analysis, EDR and DLP context, clear incident handoffs. Malware and detection: behavioral analysis, documented findings, Sigma and YARA detection concepts. Identity security: Active Directory posture, Windows identity internals, evidence-backed conclusions within authorized scope. Application assessment: scoped web and Android review, static and dynamic analysis, actionable reporting. Engineering: Rust, protocol implementation, CLI tooling, structured reporting.

These are my practice areas. Not every project below implements all of them.

03 Method

Engagement pipeline: 1 scope, 2 collect, 3 analyze, 4 validate, 5 report.

04 Featured project

ADhammer logo

ADhammer

Active Directory assessment, built around evidence.

Open-source Rust CLI for directory assessment and structured reporting. A possible finding is not proof: capability support and open validation work are tracked in the validation ledger.

Website · Source · Releases · crates.io

05 Open-source map

Open-source map of icedracon Rust libraries, grouped into identity and cryptography, transport and encoding, Windows evidence and access, and native interfaces.

Area Repositories
🟢 Identity & cryptography kerbcore · ntlmssp · dpapi-ng
🟠 Transport & encoding smb2-client · dcerpc · ms-ndr
🟣 Windows evidence & access windows-eventlog-native · windows-sddl · ad-access
🔵 Native interfaces win32-min

06 Beyond security

ECHO: a pixel-art desktop companion. It's where I explore product design, animation, and local-first software.

07 Principles

Important

Scope before action. Explicit authorization and clear boundaries.

Tip

Evidence before conclusions. Observation, inference, and proof stay separate.

Note

Clarity before noise. Focused tools, readable reports, reusable components.


CYBERSECURITY  /  OPEN SOURCE  /  BUILT WITH INTENT

Pinned Loading

  1. adhammer adhammer Public

    Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported validation, and evidence reporting.

    Rust 101 7

  2. ECHO ECHO Public

    TypeScript 20