The researcher.

I'm William Jiang — 0xwi11iam — a security researcher, systems programmer, and AI red-teaming architect based in Hong Kong. Deep technical expertise, applied with practical problem-solving.

Execution, not theory.

I build tools that make powerful technology safe, accessible, and user-friendly. My work sits at the intersection of offensive security and defensive engineering — the same hands that automate red-team pipelines also ship the dd replacement that refuses to destroy your disk.

The through-line is my belief in responsible disclosure and ethical security research. Every attack path I document ships alongside its mitigation. Every benchmark I publish exists to make models safer, not just to score them. The goal is never the exploit for its own sake — it is understanding the system deeply enough to protect the people who depend on it.

That philosophy shows up everywhere: Medusa's Blue Team SOC defends the same traffic the Red Team attacks. BreachBench measures whether an LLM can execute, because memorization is not capability. macos-evilmaid documents the attack so defenders can detect it. dd-rs and MacVault exist to keep people from losing data in the first place.

The motto

“Every vulnerability discovered is a step towards a safer internet for everyone.”

What I work with.

Languages and domains that span the full stack of offensive and defensive engineering.

AI red-teamingMedusa
LLM safety & evalBreachBench
Offensive securityKill chain
Systems programmingRust · C
Defensive engineeringSOC · detection
Applied cryptographyAES-256
Agent orchestrationLangGraph
Red & blue teamingAutonomous

Languages in production

Rust · dd-rs Python · Medusa, BreachBench C · crontastic, dd-rs Shell · MacVault, evilmaid

“Every vulnerability discovered is a step towards a safer internet for everyone.”

I don't break things for their own sake. I find the cracks before they are used against real people — then I build the tools that close them. Responsible disclosure and ethical research drive everything I do.

01

Execution, not theory

If I can't demonstrate it against a real target, it doesn't count. Proof, not promises.

02

Responsible disclosure

My attack paths ship with mitigations. My findings are reproducible, documented, and shared with defenders.

03

Tools that protect

I trade cleverness for real-world safety — from a dd that asks before it writes to a vault that leaves zero trace.

Let's talk.

Security research, collaborations, responsible-disclosure reports, or just a good conversation about systems — my inbox is open.