Build defensible systems.
Prove the controls work.
Sudo Security & Consulting is the engineering and research practice of Kevin Landry. The work spans cloud security, digital forensics, adversary simulation, detection validation, AI agent red teaming, and agentic AI security, with an emphasis on measurable controls and evidence over assumptions.
Research and engineering built to produce evidence.
SwarmKillChain
Research and engineering focused on hunting, attributing, and disrupting compromised or malicious AI-agent workflows. The project treats multi-agent coordination as an observable security problem: tool use, delegation, trust boundaries, process behavior, network telemetry, and response opportunities.
current direction: agentic swarm detection · trust attacks · intervention telemetry · SOC operator workflow
ClawdianShield
Detection-validation framework that generates controlled adversary-like state changes and measures whether SIEM, EDR, and AI-native SOC systems actually observed, correlated, and surfaced the activity.
ground truth → host observers → normalized evidence → detection scoring
Patriot Pot
Hardened Cowrie honeypot deployed on AWS to study real-world attacker behavior, post-compromise command execution, payload delivery, and persistence attempts with GreyNoise and Shodan enrichment.
48 days · 109,024 events · 2,338 source IPs · 9,409 attacker commands
USCC Binary Exploits
Format-string and ROP-chain tooling created for live competition use, including blind FSB detection, stack-canary recovery, and ret2libc workflows against 64-bit ELF targets.
competition tooling built and used during a 2nd-place USCC Cyber Bowl East finish
Security work across the full control loop.
AI Agent Red Teaming & Agentic Security
Adversarial testing and consultation for tool-using agents, prompt injection, inter-agent trust, orchestration failure, containment, monitoring, and compromised-agent telemetry.
See serviceCloud Security
AWS architecture review, IAM analysis, network segmentation, logging strategy, deception infrastructure, and least-privilege design.
See serviceDetection Engineering
Ground-truth validation, Elastic/SIEM telemetry, ATT&CK mapping, correlation testing, false-positive analysis, and detection coverage measurement.
See serviceDigital Forensics & IR
Disk and artifact analysis, timeline reconstruction, evidence preservation, malware triage, attribution, and incident-response workflow development.
See serviceAdversary Simulation
Controlled offensive validation designed around security invariants, observable state changes, defensive telemetry, and measurable response outcomes.
See serviceAI Evaluation & Benchmarking
Test-case design, containerized evaluation environments, deterministic validation, rubric design, multimodal evaluation, and model/harness failure analysis.
See serviceThe deliverable is evidence, not theater.
Define the asset, trust boundary, security property, expected observable, and stopping condition before testing.
Separate what a tool, model, or operator claims happened from the state change and telemetry that establish what actually happened.
Findings include evidence, impact, validation, remediation, and the telemetry needed to detect recurrence.
Need a focused cloud, detection, DFIR, AI-agent, or adversarial assessment? Start with a scoped request.