// security researcher · hong kong

William Jiang

Security researcher

“Every vulnerability discovered is a step towards a safer internet for everyone.”

Hamster mascot
0xwi11iam@researcher — zsh
$ whoami william_jiang — 0xwi11iam · HK $ cat /etc/motd “Every vulnerability discovered is a step towards a safer internet for everyone.” $ ./deploy --target production ✓ 6 projects · 99 lab vulnerabilities ➜ responsible disclosure, always.
$
6
Core projects
99
Lab vulnerabilities
836
Benchmark questions
85
Agent tools
360
Tests passing
250+
NL cron patterns
51
Attack skills

Projects that ship.

Six production-grade tools spanning AI red-teaming, offensive-security benchmarking, and hardened systems software.

01 / MEDUSA Python · LangGraph

Medusa

Autonomous Red & Blue Teaming — Attack and Defend with AI

An agentic red-teaming framework built on LangGraph and Re-Act. It chains recon, exploitation, and post-exploitation into one pipeline, while a Blue Team SOC defends live traffic with 18 attack-pattern detectors and AI-driven countermeasures.

85 tools 48 modules 51 skills 15 vulns in lab
LangGraph LLM agents Red & Blue Rich TUI Mermaid reports
02 / BREACHBENCH Python · Docker

BreachBench

Execution. Not Theory.

A production-grade benchmark that measures whether an LLM can actually execute the full kill chain against live targets — not recite CVEs. Four stages, five vulnerable labs, real tools, real flags.

836 questions 29 topics 5 labs 84 vulns
LLM benchmark MITRE ATT&CK Live exploitation 11 providers Dashboard
03 / DD-RS Rust · C

dd-rs

Never accidentally destroy a disk again.

A memory-safe reimplementation of Unix dd with a 5-layer safety system, zero-copy kernel transfers, and both legacy key=value syntax plus modern subcommands. Fast, auditable, and safe by default.

13+ risk factors 16 conversions 1.5–3× faster 128 KiB auto block
Rust Safety guardrails copy_file_range GNU-dd compatible
04 / MACVAULT Shell · AES-256

MacVault

AES-256 at every layer. Zero trace when locked.

A portable encrypted file store for macOS and Linux with dual-layer AES-256 encryption, multi-vault support, and a disguise mode. When locked, nothing remains — no plaintext, no metadata, no trace.

AES-256 layers 58 commits v1.0.19 stable 0 traces when locked
AES-256 APFS / LUKS Keychain Audit log Plugins
05 / CRONTASTIC C · Cron

crontastic

Write a human-readable sentence and the cron will still work.

A drop-in replacement for Vixie Cron that understands plain English. Over 250 natural-language patterns map to classic cron expressions while preserving every operator, special string, and edge case.

250+ NL patterns 7 operators 8 special strings --explain mode
Natural language Vixie superset Daemon mode Safety checks
06 / EVILMAID Shell · macOS

macos-evilmaid

A lifesaving tool for people locked out of Macs they own.

Documents a physical-access attack chain on macOS — and the mitigations that stop it. A LaunchDaemon masquerading as an Apple service persists root access across reboots, with full detection guidance for blue teams.

1 reverse shell :5500 listener 2 documented paths 0 admin password needed
Recovery Mode LaunchDaemon Persistence Mitigations

The toolchain.

Every layer chosen for a reason — memory safety, observability, portability, and speed.

Rustdd-rs
PythonMedusa · BreachBench
Ccrontastic · dd-rs
ShellMacVault · evilmaid
LangGraphMedusa
DockerBreachBench labs
MITRE ATT&CK80+ mappings
AES-256MacVault
APFS / LUKSMacVault
Rich TUIMedusa
MermaidAttack chains
LLM providersDeepSeek · Gemini · Anthropic

“Every vulnerability discovered is a step towards a safer internet for everyone.”

I don't break things for their own sake. I find the cracks before they are used against real people — then I build tools that make powerful technology safe, accessible, and useful. Responsible disclosure and ethical research power everything I do.

01

Execution, not theory

I ship benchmarks that run live exploits, not multiple-choice quizzes. If I can't demonstrate it against a real target, it doesn't count.

02

Responsible disclosure

My findings are documented, reproducible, and shared with defenders. Every attack path ships alongside the mitigations that close it.

03

Tools that protect people

From a dd that can't nuke your disk to a vault that leaves zero trace, I trade cleverness for real-world safety.