Skip to content

About

Hi, I'm Anthony.

I'm a security researcher focused on how bot-detection and anti-automation systems work, and how to make them stronger. I've spent years studying these systems from the attacker's side. My goal now is to help build the defense.

I study how the internet tells humans and machines apart — bot detection, device fingerprinting, anti-automation, mobile app protection — and I've spent years learning how those systems work from the inside out.

It started with a stubborn kind of curiosity. If something in my house breaks, I'll sit there for hours pulling it apart to figure out why it stopped working, rather than just buying a new one or calling someone — I have to know what's actually happening underneath. That's the same instinct that pulled me deep into client-side detection: the quiet layer of the web that's constantly deciding whether there's a real person behind a request. I got hooked on the puzzle of it.

Because that's what this is to me: a puzzle, the kind that pushes back. It feels like a video game against a smart opponent, where winning means thinking sideways and understanding the rules better than the people who wrote them. I have the kind of brain that locks onto a problem and won't let go until it works — and I've pointed that at understanding detection systems end to end, from the network handshake to the behavioral signals to the obfuscated code that ties it all together.

What I bring

I approach detection systems the way a red team approaches a target — adversarially, probing for where they break — but the goal is always the blue-team one: understanding the weakness so it can be strengthened. That means I understand the full anti-automation pipeline from the attacker's point of view — how these systems collect signals, how they decide who to trust, and where they hold up or fall short. I can trace through them, analyze how they're built, and explain what I find in plain language. I lean on modern tooling, AI included, to move faster and go deeper — and just as importantly, I know how to verify what it gives me rather than take it on faith.

I also come from a software background — a B.S. in Information Systems and professional experience building real-time monitoring tools and secure data systems — so I'm comfortable in real engineering environments and used to translating technical findings for people who don't live in the details.

How I work

I care about the line between research and harm, and I hold it on purpose. Everything I publish is written to explain how these systems work and how they can be made stronger — never how to break something live. Understanding is worth sharing; working attacks aren't. If you notice I stop short of the operational detail, that's deliberate. To me, knowing what to leave unwritten is part of being a researcher worth trusting.

Where I'm headed

I want to bring an attacker's-eye understanding to a detection, threat-research, or security-analyst team, and point it at protecting real people from fraud, abuse, and automated attacks. If that's the kind of problem your team works on, I'd genuinely love to talk.