Independent security research
THOR-SEC
Research on how attackers use access, and how systems can make that access worthless.
THOR-SEC finds hard security and infrastructure problems, develops original solutions, and publishes the evidence that they work. Papers, reference implementations, and labs by Thor Thor on AI and LLM security, moving target defense, and security architecture. Every claim ships with the artifacts to check it.
- Accepting research requests
- latest MIAM 1.0.0
- orcid 0009-0001-6573-385X
Latest research
Full archive-
Mission-Invariant Architecture Morphing (MIAM)
Most moving target defenses change addresses, ports, or hosts. MIAM reshapes an application's internal service graph across security epochs while its external interface stays fixed, so the dependency map an attacker builds after initial access goes stale. Includes a retention model showing that a finite variant pool leaves a nonzero knowledge floor.
-
Model Identity Verifier
Detects LLM identity drift, route or provider mismatch, and downgrade or substitution signals, without treating a model's self-description as proof of what is running.
-
BoundaryLayer
A local lab for the infrastructure boundaries that decide blast radius after a model or agent is tricked: tool routing, sessions, authorization, uploads, caching, and alerting.
Case studies
Full case-study archiveTHOR-SEC separates what is proposed, what is implemented, what is tested, and what is still unproven.
-
Implemented and tested reference implementation
LLM Agent Control Plane
A deterministic control boundary for tool-connected LLM agents, with authorization kept outside the model and mapped to automated tests.
-
Formal design; empirical validation pending
Mission-Invariant Architecture Morphing (MIAM)
A formal architecture for changing an application's internal service graph so post-access reconnaissance can lose value across security epochs.
-
Implemented prototype; live-provider release gate pending
Model Identity Verifier
A CLI that flags model identity drift, provider or route mismatches, downgrade signals, and baseline changes without treating self-description as attestation.
Research areas
- AI and LLM securityAgent authorization, tool boundaries, model identity, LLM infrastructure.
- Moving target defenseMaking post-access reconnaissance expire at the application layer.
- Security architectureGoverned, measurable security operations with explicit invariants.
- Detection engineeringBaselines, correlation logic, and detection content that holds up in operations.
- Risk quantificationEvidence-driven estimates of material impact instead of color-coded heat maps.
- Security writingReports, research notes, and books written for the people who act on them.
Open-source projects
All repositories-
Agent security
LLM Agent Control Plane
Reference implementation where agents propose actions and an external policy layer authorizes them, with identity context and audit logging.
-
LLM infrastructure
BoundaryLayer
Defensive lab that runs each scenario in vulnerable and hardened mode to show what happens after a model is tricked.
-
AI assurance
Model Identity Verifier
CLI that flags model identity drift, route mismatch, and substitution signals. Self-identification is treated as text, not attestation.
-
Risk quantification
Impact Forecast Algorithm (IFA)
Bayesian-inspired method for updating the probability of material impact from explicit evidence likelihood ratios.
-
Security architecture
Security Stack Engineering (SSE)
Nine-layer reference architecture for governed, measurable security operations with explicit inputs, outputs, and invariants.
-
Moving target defense
MIAM reference materials
LaTeX source, figures, and a script that reproduces every number in the MIAM paper.
Writing
Unique Violation on Substack-
Book
Exploit the Reader: Cybersecurity Writing for Reports That Survive Reality
-
Book
Prompting as a Programming Language: A Practical Guide to Prompt-Oriented Programming, AI Workflows, and Automation
Selected essays
- The 15 Failure Points Hiding Inside Every LLM APILLM API security
- A Model That Says “No” Is Not a FirewallAgent security
- The MCP Attack Surface: Why Your AI Agent’s New “USB-C Port” Is a Remote Execution TierMCP attack surface
- skill.md Is an Unsigned Binary With Your KeysSupply chain
Work with THOR-SEC
Bring THOR-SEC a hard problem
THOR-SEC takes on a small number of commissioned engagements: agent and AI security, system trust, and security architecture problems that routine tools do not answer. Results are labeled by strength of evidence and come with the artifacts behind them.
See how it works: problems worth bringing, what comes back, and publication, confidentiality, and IP terms.
Support independent research
THOR-SEC is self-funded. Support pays for lab infrastructure, compute, and the time to publish research and tools openly.
Connect
Research questions, collaboration, and responsible disclosure. Do not send secrets, credentials, customer data, or exploit code in a first message.
- Emailcodethor@gmail.com
- ORCID0009-0001-6573-385X
- GitHubcodethor0
- LinkedInThor Thor
- SubstackUnique Violation
- DisclosureSite security · Inventions