Claes Gyllhamn, Chaos Gremlin Engineering

Security engineering, purple-team infrastructure, and pragmatic automation.

I am a security professional and developer focused on building systems that make security work repeatable: scoped audits, lab-backed validation, detection-aware testing, and automation that can be reviewed instead of merely trusted.

This site is the public window into that work. It covers the SAGA purple-team lab, authorized research methodology, sanitized writeups, and the engineering decisions behind the tooling.


What I Can Help With

  • Security review and audit: Scoped assessment, reproducible findings, practical remediation advice, and clear handoff documentation.
  • Purple-team lab design: Active Directory ranges, application targets, telemetry expectations, evidence capture, and exercise documentation.
  • Platform and DevSecOps automation: Python/Go tooling, CI-style validators, deployment guardrails, static publishing workflows, and operational runbooks.
  • Detection-aware infrastructure: Sysmon, Wazuh, Velociraptor, Malcolm, Zeek, Suricata, OpenSearch, and the supporting data flows around them.
  • AI-assisted operations: Local-first model routing, MCP/capability servers, knowledge-RAG, approval gates, and redaction-aware workflows for sensitive environments.

Selected externally discussable tooling includes n8n, Proxmox, Docker, Nginx, Hugo, LiteLLM, LM Studio, Ollama, ComfyUI, OpenBao, and NetBox.


Working Style

  • Scope first: Testing stays inside written boundaries.
  • Evidence over theater: Findings should be reproducible, explainable, and useful to the team that has to fix them.
  • Small sharp tools: Prefer simple scripts, static outputs, and explicit validators over fragile platform sprawl.
  • Public by design: Anything published here is sanitized and separated from private lab state.

Badges & Proof Points

  • Hack The Box Badge: 52379
  • TryHackMe Badge: 17751

Contact & Core Links