Skip to content
View grassclaw's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Block or report grassclaw

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
grassclaw/README.md

Aaron E

AI Security Strategist · Systems Thinker · Founder of 0xSpectra

Agentic AI Threat Intelligence AI Governance

LinkedIn Thesis OpenSSL Speaker ISCAP 2025


I work on security as a systems problem. Give me a messy real-world substrate — certificates, malware, domains, threat feeds, models — and the job is the same: decompose it, build the system that makes sense of it, and reason about how it behaves under an adversary.

Right now that lens is pointed at an intersection few people occupy — agentic AI architecture, threat intelligence, and enterprise AI governance — designing the AI security systems large organizations trust to run in production, and deriving the strategy and frameworks from building them.


🎓 Education & Research

M.S., Cyber, Information & Operations (thesis track)University of Arizona, conferred 2026

"AI Minimalism: Necessity-First Security Design for Intelligent Systems"

The next phase of AI security isn't bigger models — it's better systems: justified, minimal, and accountable. 📄 Read the thesis →

Four ideas it introduces:

Principle The idea
Necessity-First design Every guardrail must justify its cost against the risk it removes.
Challenge Gates Human-centric checkpoints where intervention actually matters.
Governance-as-Code Controls expressed as machine-checkable artifacts, not PDFs.
Policy-as-Code Continuously detect policy drift between stated policy and running behavior.

AI Minimalism is one framework under the 0xSpectra umbrella — my independent research lab & publication. Its publication, Spectral Analysis, decomposes hard security systems into the parts that actually matter, one issue at a time.


🧰 Toolbox


🔬 Selected public work

JA4 + ML to fingerprint operating systems in encrypted traffic — a systems lens on what TLS metadata still reveals.

ABAC-driven ML policy simulating governed, attribute-based access control over automated traffic.

RetrographyRust · RetrographyPy Rust · Python

Steganography detectionretego, Latin for "uncover." Surfacing covert channels hidden inside other media.

RAG pipeline on AWS Bedrock for document analysis — applied LLM systems on managed infra.

🚧 In progress — AI Minimalism tooling: a guardrail cost analyzer (is this control's overhead justified by the risk it removes?), a policy-drift detector, and governance-as-code references — turning the thesis into things you can run.


📊 GitHub

GitHub stats Top languages

🎤 Two-time OpenSSL Conference speaker — 2025 · Prague 2026 → 📰 Peer-reviewedISCAP 2025 proceedings →

Open to advisory conversations on secure agentic architecture, AI evaluation, and AI governance.

Pinned Loading

  1. grassclaw.github.io grassclaw.github.io Public

    Webpage Trial

    TypeScript 1

  2. grassclaw grassclaw Public

    Aaron Escamilla — AI Security Strategist & Systems Thinker