System Architect · Security Researcher · Photographer
Morteza
Bahmani
Independent creator exploring the intersection of security, infrastructure, and digital craft. Building at Internet Labs.
Blog
Recent writings on security, infrastructure, and the open web
Autonomous Vulnerability Discovery: Replacing Static SAST with Adversarial Verifiers
Static code scanners drown engineering teams in unverified alerts. Autonomous security harnesses now combine determinist…
Oryxis vs SSHPilot: Architectural Trade-offs in Modern Remote Shell Clients
A technical evaluation of Oryxis and SSHPilot, comparing local ChaCha20-Poly1305 encrypted vaults, GTK4 versus Rust runt…
Why Agent-Driven Code Review Needs Real-Time Observability Hooks
Agent code review tools ship blind without observability into LLM decisions. Learn five steps to instrument your agent p…
witr: Tracing Process Start Chains
ps and lsof show what is running, not why. witr walks the ancestry: PID to supervisor to the script that started it, in …
bgscan vs WebCheck-OSINT: Two Ways to Run an Engagement Recon Pass
bgscan sweeps networks from a BubbleTea TUI, chaining ICMP, TCP, HTTP, DNS, and tunnel probes into one run. WebCheck-OSI…
Why MoE Models Stream From NVMe: Kernel Prefetch, Read-Ahead, and Async I/O
Frontier MoE models run on consumer hardware by streaming expert weights from disk. Not compression—kernel I/O prefetchi…
Older Posts
Movie Diaries
from Letterboxd Letterboxd
Projects
01 / 04Things I'm building and contributing to
