Samson Laird

Samson Laird

Also known as SAMSON

IT Support Engineer. Red teaming. Agentic security. OSCP in progress.

GitLab WattoCyber
LinkedIn in/sam-laird
Hack The Box Samsonnn
Location St. Louis, Missouri
324injection techniques cataloged
101CTF writeups
16public projects
100+machines rooted

Home lab

Home lab rack: Pi tray, Proxmox cluster, UniFi switches, firewall and CloudKey, backup NUC, Jetson, UGREEN NAS, UPS, and an ASUS GB10 Spark on top.
  • GB10 DeepSeek Spark
  • Pi tray Pi-hole, Uptime Kuma, Prom/Grafana, kiosk, local search
  • Proxmox cluster and backup NUC
  • Edge UniFi, firewall, CloudKey
  • Storage / GPU UGREEN NAS, Jetson Orin

Projects

Loading projects…

  • White-box research
    Gradient Untangler

    Local research harness that searches for the exact tokens that make an open-weight model start its answer the way you specify. White-box gradient attack on weights you already possess; remote APIs rejected.

    pip installable · local weights only

      Python PyTorch CLI
  • Agent forensics
    MASQ

    Local security CLI for AI agent stacks. Sits in the seat the model sits in: reads MCP catalogs and OpenAI-compatible HTTP the way the client does, reports what the model can actually see.

    cargo build --locked · bash scripts/demo.sh

      Rust MCP CI
  • OSCP toolkit
    Custom OSCP Tooling

    Read-only, OSCP-exam-safe tooling: cantina network recon orchestrator plus Star Wars-named enum, privesc-scan, hash-ID, and advisor scripts. Nothing modifies a target.

    python -m pytest tests/ -q · MIT

      Python CLI NSE bash
  • Reference
    LLM Injection Field Guide

    Catalog of prompt-injection and jailbreak techniques. Every attack card has a defense field.

    Live catalog · single index.html · CC BY 4.0

      HTML KaTeX zero-build
  • Defense library
    StegOFF

    Pre-ingest gate: scan text and files for steganography and prompt injection before they hit an LLM or agent. Clean what you can.

    python scripts/repro.py → REPRO_OK · offline pytest

      Python CLI API
  • Control plane
    Agentic DM Gateway

    Security control plane in front of LLM agents on private DMs. Who may talk, session unlock, kill switch, and message safety stay separate from the model.

    python scripts/repro.py → REPRO_OK · security unit tests

      Python Discord CI
  • Tripwires
    Agent Canary

    Tripwire detection for autonomous agents: file, MCP, and API honeypots that fire when something touches them.

    Public package + tests

      Python MCP honeypots
  • Eval lab
    Agent Trap Lab

    AI web-browsing agent trap lab: adversarial pages, StegOFF defense matrix, and an Ollama evaluation harness that publishes defended vs gap verdicts.

    Detector unit tests offline

      Python Ollama StegOFF
  • MCP auth
    nostr-mcp-auth

    Fail-closed NIP-98 authentication for HTTP MCP servers. No proof, no tools. Wrong key, bad sig, stale event, or body swap returns 401.

    nostr-mcp-auth quickstart · serve · call

      Python NIP-98 Nostr
  • Agentic research
    Equity Research Agent

    Natural-language equity research agent: plain English in, grounded market research out (price, technicals, fundamentals, SEC, news, X, charts, heatmaps, thesis memory).

    Public main branch · agent-focused default install

      Python Anthropic FastAPI yfinance Discord Docker
  • OSCP recon
    Cantina

    OSCP-legal network recon orchestrator: port scan, service enum plugins, multi-target timeouts. Enumeration only. No exploit auto-run.

    pytest suite

      Python pytest
  • Enum tooling
    vegadns

    High-concurrency subdomain enum and HTTP path discovery in one binary. Lab F1 measured against massdns / dnsx / ferox-class tools.

    docs/BENCHMARKS.md · lab suites only

      Rust DNS HTTP
  • Field notebook
    OSCP notes 2026

    OSCP field notebook, now the single vault for methodology that used to live in five separate repos: credential dumping, DLL attacks, UAC bypass, one-liners, and the bug bounty hunt ladder. Commands first.

    Public methodology vault · 512+ notes · consolidated

      Markdown Obsidian Python
  • Defense library
    Detection Defense Library

    One consolidated defense-engineering library: attack classes, the patterns that detect them, committed Sigma rules indexed to MITRE ATT&CK, and the Windows trust-boundary model in a single repo.

    Consolidated repo · patterns + sigma + boundaries + drivers + splunk

      Markdown Sigma Splunk SPL
  • Recon
    LM-Fingerprint

    Fingerprints the serving stack behind an OpenAI-compatible chat endpoint: tokenizer accounting, template offsets, JSON/SSE shape, role acceptance, named limits, gateway headers.

    pip install lm-fingerprint · MIT

      Python OpenAI API CLI
  • Agent skills
    Skill Library

    Own-authored agent skills, each a self-contained SKILL.md: testable procedure over vague ceremony. Original work only; no bundled-skill republishing.

    gitlab.com/WattoCyber/skill-library · MIT

      Markdown SKILL.md

Background

  • Environmental Restoration LLC

    IT operations · 2022-present

    Two-person IT team, ~300 users nationwide, CMMC Level 2 environment. Own pieces of Device Control, BitLocker architecture, Autopilot modernization, and control-mapped policy work (NIST 800-171).

    Completed
  • Offensive security

    OSCP in progress · lab and CTF

    OSCP in progress. 100+ machines rooted across HTB, Proving Grounds, TryHackMe, and VulnHub. Active Directory chains, Linux and Windows privilege escalation. Writeups published for retired boxes.

    In progress
  • B.S. Cybersecurity

    Maryville University · 2025

    Three tracks: risk and compliance, offensive methods, and defensive operations. Graduated 2025.

    Completed

Connect

Hiring, collab, or lab access.

Message for hiring, collab, or lab access… Email