Claes Gyllhamn · Security Engineer · Malmö

Security engineering with a working lab behind it.

I build scoped security reviews, purple-team lab infrastructure, and automation-backed remediation workflows for teams that need evidence instead of theater.

Services

I am most useful where security, infrastructure, and automation overlap: findings need to be reproducible, defenses need to be observable, and the fix path needs to survive handoff.

Security Review & Audit

Application, platform, and workflow review with scope boundaries, reproducible evidence, and prioritized fixes.

Purple-Team Lab Design

Repeatable ranges, detection exercises, telemetry plans, and documentation that make security practice measurable.

DevSecOps Automation

Scripts, validators, deployment guardrails, and operator workflows that reduce manual drift and risky handoffs.

AI-Assisted Operations

Local-first agent workflows, knowledge-RAG patterns, approval gates, and redaction-aware automation for sensitive environments.

Selected Work

SAGA Purple-Team Platform

Overview of the lab-backed range used to validate attack paths, telemetry, evidence capture, and AI-assisted operator workflows.

WordPress Full-Chain Lab

A sanitized chain from initial web weakness through evidence, detection opportunities, cleanup, and remediation guidance.

Architecture Notes

External-facing decisions about local-first AI routing, redaction boundaries, capability servers, and static publishing.

Writeup Archive

Older CTF and technical walkthroughs retained as a learning archive, separate from current research positioning.

What's Here

  • Services: How I scope work, what I deliver, and where I am a good fit.
  • Research: Authorized security methodology, scope rules, and sanitized findings.
  • Lab and SAGA: Sanitized lab notes and platform overview.
  • About and Contact: Profile, links, and ways to reach me.

Public pages are intentionally scrubbed for secrets, private telemetry, internal host details, and live operator runbooks.