Security engineering across cloud, endpoints, and autonomous systems

Build defensible systems.
Prove the controls work.

Sudo Security & Consulting is the engineering and research practice of Kevin Landry. The work spans cloud security, digital forensics, adversary simulation, detection validation, AI agent red teaming, and agentic AI security, with an emphasis on measurable controls and evidence over assumptions.

AWS SecurityDFIRDetection EngineeringAI Agent Red TeamingAgentic AI SecurityAdversary Emulation
Security Validation Architectureevidence-driven
Attack & Evaluation Plane
controlled execution
Cloud & Telemetry Plane
independent observation
Evidence & Decision Plane
109K+honeypot security events analyzed
48 dayscontinuous AWS deception research
2ndUSCC Cyber Bowl East
M.S.Digital Forensics candidate, GMU
Current & selected work

Research and engineering built to produce evidence.

Agentic AI Security · Active Research↗

SwarmKillChain

Research and engineering focused on hunting, attributing, and disrupting compromised or malicious AI-agent workflows. The project treats multi-agent coordination as an observable security problem: tool use, delegation, trust boundaries, process behavior, network telemetry, and response opportunities.

current direction: agentic swarm detection · trust attacks · intervention telemetry · SOC operator workflow

Detection Validation · Docker · Elastic↗

ClawdianShield

Detection-validation framework that generates controlled adversary-like state changes and measures whether SIEM, EDR, and AI-native SOC systems actually observed, correlated, and surfaced the activity.

ground truth → host observers → normalized evidence → detection scoring

AWS · Deception · Threat Intelligence↗

Patriot Pot

Hardened Cowrie honeypot deployed on AWS to study real-world attacker behavior, post-compromise command execution, payload delivery, and persistence attempts with GreyNoise and Shodan enrichment.

48 days · 109,024 events · 2,338 source IPs · 9,409 attacker commands

Exploit Development · CTF · Binary Analysis↗

USCC Binary Exploits

Format-string and ROP-chain tooling created for live competition use, including blind FSB detection, stack-canary recovery, and ret2libc workflows against 64-bit ELF targets.

competition tooling built and used during a 2nd-place USCC Cyber Bowl East finish

Core capabilities

Security work across the full control loop.

AI

AI Agent Red Teaming & Agentic Security

Adversarial testing and consultation for tool-using agents, prompt injection, inter-agent trust, orchestration failure, containment, monitoring, and compromised-agent telemetry.

See service
AWS

Cloud Security

AWS architecture review, IAM analysis, network segmentation, logging strategy, deception infrastructure, and least-privilege design.

See service
DET

Detection Engineering

Ground-truth validation, Elastic/SIEM telemetry, ATT&CK mapping, correlation testing, false-positive analysis, and detection coverage measurement.

See service
DF

Digital Forensics & IR

Disk and artifact analysis, timeline reconstruction, evidence preservation, malware triage, attribution, and incident-response workflow development.

See service
RED

Adversary Simulation

Controlled offensive validation designed around security invariants, observable state changes, defensive telemetry, and measurable response outcomes.

See service
EVAL

AI Evaluation & Benchmarking

Test-case design, containerized evaluation environments, deterministic validation, rubric design, multimodal evaluation, and model/harness failure analysis.

See service
Operating model

The deliverable is evidence, not theater.

Scope precisely.
Define the asset, trust boundary, security property, expected observable, and stopping condition before testing.
Measure independently.
Separate what a tool, model, or operator claims happened from the state change and telemetry that establish what actually happened.
Ship usable output.
Findings include evidence, impact, validation, remediation, and the telemetry needed to detect recurrence.

Need a focused cloud, detection, DFIR, AI-agent, or adversarial assessment? Start with a scoped request.

GIAC GCIH
GIAC GSEC
GIAC GFACT
CompTIA Security+
CSA TAISE