NAME

About me

ABOUT

Thomas Barabosch

FOCUS

Hi there, I am Thomas Barabosch, a senior security IC working across systems security, reverse engineering, threat research, incident response, cloud security, and AI-enabled security tooling.

I like the parts of security where careful technical analysis turns into something useful: better detections, clearer investigations, stronger tooling, and a deeper understanding of how systems fail. My work moves between low-level details and operational questions: disassemblers, binaries, firmware, exploit primitives, cloud environments, actor tradecraft, incident scoping, hunting ideas, and analyst workflows.

BACKGROUND

I have built and contributed to open-source security projects, including FACT, cwe_checker, and ForgeArmory. I have also published scientific papers, presented at conferences, submitted patches and vulnerability reports to BSD projects and other software vendors, and served for many years on the programme committee of Botconf.

Operationally, I care about turning research into response: threat actor tracking, malware and infrastructure analysis, detection engineering, cloud and enterprise security investigations, incident scoping, stakeholder-ready findings, and tools that reduce analyst toil. Recently that has included AI-enabled workflows for triage, case tracking, and repeatable security operations.

WRITING

This blog is where I write down technical material that should last longer than a short post elsewhere: reverse-engineering notes, malware and threat research, systems security experiments, tool write-ups, cloud and security-operations observations, incident-response lessons, book recommendations, and the occasional personal opinion about cyber security.

CONTACT

You can find my projects on GitHub and my professional profile on LinkedIn.

The posts here are my own and reflect my personal views, not those of any past, current, or future employer.