Become a sponsor to After Packet
Support AfterPacket's open sourceMy name is Jordan Lassiter — most people know me as AfterPacket. I got the
handle at DefCon 25 in 2017 from a name generator and never bothered to pick
another one.
I build open-source cybersecurity tools for defenders who'd rather understand
attackers than just block them. My work spans five areas:
Deception engineering — Drosera is
a multi-protocol honeypot platform that impersonates real services, tarpits
attackers, and records every interaction. Utricularia
extends that to ICS/SCADA, presenting a Schneider Modicon PLC over Modbus/TCP
and EtherNet/IP with a simulated pump station behind it. Both are named after
carnivorous plants because that's how they trap — by adhesion and by suction.
Published threat intelligence — Drosera Threat Intel
ships YARA rules, Suricata rules, IOC feeds, firewall block entries, and full
written reports for every capture. I document why each indicator is included
and why each candidate was excluded. Shared CDN ranges never make the feed.
Signatures that would false-positive across a real estate don't ship. The
master blocklist is a plain text file you can curl on a cron.
AI security — Vexor is a full
OWASP GenAI Top 10 red-teaming platform with multi-provider support, automated
jailbreak testing, mutation engines, and synthetic attack generation. If your
model has a weakness, it finds it before someone else does.
Anti-abuse systems — Pow-Shield
is a proof-of-work framework for PHP and WordPress. Adaptive SHA-256 puzzles,
no CAPTCHA, no JavaScript fingerprinting, no third-party services. Bots solve
math; humans never see anything.
Internet measurement — partially.online
aggregates IODA, GDELT, Cloudflare Radar, and RIPE Atlas to monitor worldwide
censorship and outages in real time, correlating connectivity drops against
real-world events.
Why sponsorship matters
Everything I build is free and open source. No paywalls, no "enterprise"
tiers, no telemetry phoning home to a third party. I self-host my own
infrastructure — Proxmox, Docker, Elastic — because I don't trust services
that I can't audit, and I don't think other defenders should have to either.
But infrastructure costs money. Servers, bandwidth, domains, and the time to
maintain all of it — that's what sponsorship covers. It also buys me time to
do the unglamorous work: writing detection rules at 2 AM because a honeypot
caught something new, triaging false positives so the blocklist stays clean,
documenting the reasoning behind every signature so other defenders can verify
my work instead of trusting it on faith.
If any of my tools have been useful to you — if you've pulled the blocklist,
run Drosera, used Vexor to test your model, or just read a report — a
sponsorship keeps that work going.
What I'm building next
- Drosera v1.0 — stable release of the core deception platform
- Utricularia protocol expansion — DNP3 and S7comm support for broader
ICS/SCADA vendor coverage - Attacker replay system — record a session from one honeypot, replay it
against another to test detection coverage - Public REST API for honeypot telemetry so other tools can pull feeds
programmatically - AI-powered IOC enrichment — correlating captures against threat feeds
without manual triage - Internet censorship timeline — a historical record, not just a live view
Every attacker interaction is an opportunity to learn. Sponsorship turns that
opportunity into published, verified, open intelligence that makes every
defender stronger — not just the ones who can afford a vendor contract. work