Skip to content
View tweedge's full-sized avatar
🦝
what the devs know: 1. whole codebase is spaghetti 2. spaghetti is delicious
🦝
what the devs know: 1. whole codebase is spaghetti 2. spaghetti is delicious

Organizations

@foodtrax @partridge-tech @securitygolf @DeepCISO @r-cybersecurity @mouseparty-org

Block or report tweedge

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tweedge/README.md

Hi, I'm Chris 👋

I'm a security person in a software world. My focus is on bringing holistic and pragmatic security solutions to software companies, and I'm especially partial to risk-reducing solutions which improve development processes or developer experience (bingo!).

Currently, I'm a Cloud Security manager @ Amazon as part of the Application Security organization. Corporate-speak aside, we reduce the cost of securing Amazon's applications in the cloud and promote long-term sustainable architecture, and we eliminate more annualized risk than our salaries and infrastructure costs. Sometimes we're building tools to 'shift left' in cool or unusual ways, sometimes we're pushing the limits of what issues can be detected from analyzing infrastructure at scale. My team is not the "run ScoutSuite and call it a day" type, thankfully. :)

My notable past roles include:

  • Sr. Security Engineer, Amazon (completing an L4-through-L6 IC journey)
  • Security Engineer, Vulnerability Management @ Luta Security on the Zoom contract
  • Product Security Engineer @ Datto, and Software Engineer before that

I do security research across many topic in my spare time (read: whatever grabs my interest, little real theme), and either dump half- to fully-baked repos on GitHub or publish posts on my blog. If you'd like to chat or connect, you can find my social media and ways to message me on my contact page.

Pinned Loading

  1. springcore-0day-en springcore-0day-en Public

    Everything I needed to understand what was going on with "Spring4Shell" - translated source materials, exploit, links to demo apps, and more.

    Python 107 35

  2. ru-ok ru-ok Public

    Checking the status of Russian internet properties (via RIPE Atlas) being targeted by Ukraine's hacktivist "IT ARMY" Telegram group (and others).

    Python 18 5

  3. emerging-threats-pihole emerging-threats-pihole Public

    Block malware on your network using your PiHole, using threat intelligence extracted from Emerging Threats rulesets.

    Python 70 3

  4. unishox2-py3 unishox2-py3 Public

    A package for Unicode-friendly string compression using Unishox2

    Python 23 2

  5. Netflix-Skunkworks/policyuniverse Netflix-Skunkworks/policyuniverse Public

    Parse and Process AWS IAM Policies, Statements, ARNs, and wildcards.

    Python 444 61

  6. quickburn quickburn Public

    Forked from da667/dns2snort

    Given a file containing a list of fully qualified DNS domains, quickburn generates IDS rules which detect those domains (and their subdomains) in DNS queries, HTTP Host header, SNI in TLS ClientHel…

    Python 2