Claes Gyllhamn, Chaos Gremlin Engineering
Security engineering, purple-team infrastructure, and pragmatic automation.
I am a security professional and developer focused on building systems that make security work repeatable: scoped audits, lab-backed validation, detection-aware testing, and automation that can be reviewed instead of merely trusted.
This site is the public window into that work. It covers the SAGA purple-team lab, authorized research methodology, sanitized writeups, and the engineering decisions behind the tooling.
What I Can Help With
- Security review and audit: Scoped assessment, reproducible findings, practical remediation advice, and clear handoff documentation.
- Purple-team lab design: Active Directory ranges, application targets, telemetry expectations, evidence capture, and exercise documentation.
- Platform and DevSecOps automation: Python/Go tooling, CI-style validators, deployment guardrails, static publishing workflows, and operational runbooks.
- Detection-aware infrastructure: Sysmon, Wazuh, Velociraptor, Malcolm, Zeek, Suricata, OpenSearch, and the supporting data flows around them.
- AI-assisted operations: Local-first model routing, MCP/capability servers, knowledge-RAG, approval gates, and redaction-aware workflows for sensitive environments.
Selected externally discussable tooling includes n8n, Proxmox, Docker, Nginx, Hugo, LiteLLM, LM Studio, Ollama, ComfyUI, OpenBao, and NetBox.
Working Style
- Scope first: Testing stays inside written boundaries.
- Evidence over theater: Findings should be reproducible, explainable, and useful to the team that has to fix them.
- Small sharp tools: Prefer simple scripts, static outputs, and explicit validators over fragile platform sprawl.
- Public by design: Anything published here is sanitized and separated from private lab state.
Badges & Proof Points
Contact & Core Links
- GitHub Profile: github.com/kryssar
- LinkedIn Connection: linkedin.com/in/claesgyllhamn
- Twitter/X Feed: twitter.com/clgyl