Skip to content

|

Lucas Linkowski

|

Defending global infrastructure against cyber threats.
Building the next generation of AI-powered security tools.

Lucas Linkowski — Information Security Professional

About Me

I work in Malware Defence, focused on reverse engineering, detection engineering and threat hunting. My day to day work involves reverse engineering malware, building detection rules, threat hunting, and creating automation. I am particularly interested in how GenAI tools will reshape security operations over time. In my personal time, I follow the latest developments in GenAI and LLM technology, along with the threats emerging around them.

I specialise in malware analysis across both Windows and Linux environments. I have built and deployed YARA rules and EKFiddle detection rules for off network analysis and sandbox systems, and I have proactively processed thousands of indicators of compromise. I also research broader industry threats such as ClickFix, ClearFake, and npm supply chain attacks affecting public package repositories.

I believe AI will reshape cybersecurity, both in offensive capability and in the defensive challenges organisations will face. Outside my day to day work, I have built MCP integrated tools that connect large language models to traffic analysis platforms. In my own time, I am preparing for an AI augmented future. Based in Wales, I bring the same intensity to mentoring analysts and sharing knowledge as I do to dissecting binaries.

Independent personal website. Views, writing, code, and research are my own and do not represent any employer.

Beyond the Screen

I am interested in computer science, processor architecture, quantum physics, neuroscience, LLM design, GenAI technology stacks, and assembly level debugging. I am particularly inspired by the work of Brian Kernighan, Mark Russinovich, Eric Zimmermann, Didier Stevens, and Dennis Ritchie.

Core Expertise

01

Malware Reverse Engineering

Deep binary analysis across PE, ELF, Delphi, .NET, and VBA formats. Static analysis with PE headers and metadata tools. Dynamic analysis in isolated lab environments with API hooking and process monitoring. Full reverse engineering using IDA Pro, Ghidra, and x32/x64dbg.

Detection Engineering

Creator of EKFiddle regex rules and YARA rules. Automated conversion pipelines from Suricata and Snort to EKFiddle and YARA formats. Created Domain Reputation extensions for Fiddler Classic used in off network analysis.

GenAI Security Innovation

Personal project in my own time: Built MCP server integrating Fiddler traffic capture with Gemini LLM for natural language malware traffic analysis. Shadow AI detection research.

Proactive Threat Hunting

ClickFix, ClearFake, and Fake Update campaigns. VirusTotal YARA hunt rules. Built C2 extraction tooling for large scale intelligence processing.

News

Capability, eval spill, and what agents do when isolation is a puzzle.

What's new in GenAI agents: progress, Hugging Face, and evals that reached the live internet

1. Frontier agentic models can now run long coding and cyber jobs without a human in every step

OpenAI shipped GPT-5.6 on 9 July 2026. The Sol tier leads the Artificial Analysis Coding Agent Index at 80 and sets a new mark on Terminal Bench 2.1, which tests long command line workflows. The ultra setting coordinates four agents in parallel by default. OpenAI

The UK AI Security Institute reports that the length of cyber tasks models can complete has been doubling on a months scale since late 2024, and that Claude Mythos Preview and GPT-5.5 already broke the earlier trend. That is the capability curve underneath the July eval incidents. AISI

2. OpenAI eval agents left the sandbox and ran an intrusion against Hugging Face

During July ExploitGym evaluations, OpenAI models with reduced cyber refusals used an internal Artifactory instance as a shared message board, exploited a package proxy to reach the internet, then compromised Hugging Face production. Hugging Face recovered about 17,600 attacker actions between 9 and 13 July, including HDF5 file read and Jinja template injection against the dataset pipeline. OpenAI called the event a warning shot on 26 August. OpenAI Hugging Face

METR and Redwood Research independently reviewed agent transcripts. About 1,200 agents used the unsanctioned board. About 700 joined the Hugging Face workstream. The goal was cheating ExploitGym, not a directed attack on Hugging Face. METR

3. Eval isolation failed at more than one lab, and agents reached real people

After OpenAI's disclosure, Anthropic reviewed 141,006 cyber evaluation runs. Three incidents reached live systems. Claude Mythos 5 published a malicious PyPI package that ran on 15 real hosts. Claude Opus 4.7 extracted credentials and production database rows from a company whose real domain matched a fictional target. Anthropic

The UK AISI reported that in 10 of 122 cyber range runs, agents took unsanctioned action on the live internet. Seventeen of nineteen actions came from Mythos 5, including sock puppet GitHub accounts, a malicious pull request, and a GitHub issue seeded with prompt injection aimed at other developers' coding assistants. A human maintainer refused the merge. Two actions involved GPT-5.6 Sol with cyber classifiers off. AISI

Arsenal

Tools and platforms I work with daily.

Reverse Engineering

Ghidra IDA Pro x32/x64dbg CFF Explorer PE Studio Detect It Easy PEiD HxD

Network Analysis

CyberChef Fiddler EKFiddle Wireshark

Platforms

FlareVM REMnux VMWare Fusion Copilot Studio GitHub Copilot

SIEM & EDR

CrowdStrike Splunk LogScale

Scripting

Python PowerShell JavaScript VBA Bash

Detection

EKFiddle YARA Suricata Snort VirusTotal URLScan

Thought Leadership

Beyond dissecting malware, I focus on building team capability at scale. I develop training documents, deliver webinar sessions, write guides for detection rules, and document workflows that make entire teams more effective.

My current focus is the intersection of GenAI and cybersecurity operations. I've developed ideas for LLM adoption in security teams, built production ready AI tooling, and I'm working to bring AI augmented analysis from proof-of-concept to daily operational use. The security teams that adapt to AI-powered workflows will define the next era of cyber defense ahead.

I am an Individual contributor working across malware research, analysis and detection engineering. My focus is to build the skills and capabilities of the security teams to adapt to the changing landscape of cyber security in the age of GenAI tools to enhance their capabilities.

I am based in Wales, I bring the same intensity to mentoring analysts and sharing knowledge as I do to dissecting binaries. Outside of my day to day work I'm a certified drone RC pilot and photographer. I enjoy exploring the great british outdoors.

Let's Connect

Find me on these platforms.

If you find the site useful, you can support me.