About
Thor Thor
Independent security researcher, builder, and author. Founder of THOR-SEC.
Background
Thor Thor researches how attackers turn access into advantage, and how systems can be designed so that advantage does not last. His work spans AI and LLM security, moving target defense, security architecture, detection engineering, and risk quantification.
His background is in security operations and engineering: endpoint detection and response, SIEM and log pipelines, incident response and root cause analysis, and the automation that holds them together. That operational grounding shapes the research, which aims for results security teams can put to work.
THOR-SEC research is self-directed, conducted on his own time, and published with reproducible methods. It is not sponsored by, affiliated with, or representative of any employer.
Mission
THOR-SEC finds hard security and infrastructure problems, develops original solutions, and publishes the evidence that they work.
THOR-SEC exists to build independent, verifiable, credited work: research that belongs to the people who did it, with the evidence attached. The long-term goal is a lab of people who look at a hard problem, see the solution others overlook, and prove that it works.
Core competencies
Selected experience
More than ten years across IT, security operations, and engineering. THOR-SEC research is independent, self-directed, and not affiliated with or representative of any employer.
- Technical support engineering
- Security operations and engineering
- Software engineering
- Technical operations and SIEM administration
- Software quality assurance
- Enterprise IT support
Records and profiles
- ORCID0009-0001-6573-385X
- GitHubcodethor0
- LinkedInThor Thor
- SubstackUnique Violation
- CredlyBadge portfolio
- CourseraLearning profile
Responsible use
THOR-SEC research and tools are for systems, networks, and data you own or are explicitly authorized to test. THOR-SEC does not support unauthorized access, credential theft, phishing, data exfiltration, malware deployment, denial of service, or any activity intended to cause harm.