About
Hi, I'm Anthony.
I'm a security researcher focused on how bot-detection and anti-automation systems work, and how to make them stronger. I've spent years studying these systems from the attacker's side. My goal now is to help build the defense.
I study how the internet tells humans and machines apart — bot detection, device fingerprinting, anti-automation, mobile app protection — and I've spent years learning how those systems work from the inside out.
It started with a stubborn kind of curiosity. If something in my house breaks, I'll sit there for hours pulling it apart to figure out why it stopped working, rather than just buying a new one or calling someone — I have to know what's actually happening underneath. That's the same instinct that pulled me deep into client-side detection: the quiet layer of the web that's constantly deciding whether there's a real person behind a request. I got hooked on the puzzle of it.
Because that's what this is to me: a puzzle, the kind that pushes back. It feels like a video game against a smart opponent, where winning means thinking sideways and understanding the rules better than the people who wrote them. I have the kind of brain that locks onto a problem and won't let go until it works — and I've pointed that at understanding detection systems end to end, from the network handshake to the behavioral signals to the obfuscated code that ties it all together.
What I bring
I approach detection systems the way a red team approaches a target — adversarially, probing for where they break — but the goal is always the blue-team one: understanding the weakness so it can be strengthened. That means I understand the full anti-automation pipeline from the attacker's point of view — how these systems collect signals, how they decide who to trust, and where they hold up or fall short. I can trace through them, analyze how they're built, and explain what I find in plain language. I lean on modern tooling, AI included, to move faster and go deeper — and just as importantly, I know how to verify what it gives me rather than take it on faith.
I also come from a software background — a B.S. in Information Systems and professional experience building real-time monitoring tools and secure data systems — so I'm comfortable in real engineering environments and used to translating technical findings for people who don't live in the details.
How I work
I care about the line between research and harm, and I hold it on purpose. Everything I publish is written to explain how these systems work and how they can be made stronger — never how to break something live. Understanding is worth sharing; working attacks aren't. If you notice I stop short of the operational detail, that's deliberate. To me, knowing what to leave unwritten is part of being a researcher worth trusting.
Where I'm headed
I want to bring an attacker's-eye understanding to a detection, threat-research, or security-analyst team, and point it at protecting real people from fraud, abuse, and automated attacks. If that's the kind of problem your team works on, I'd genuinely love to talk.
Get in touch