π‘οΈ I'm Iason (Jason) Somarakis β Senior Penetration Tester based in Crete, Greece
βοΈ Offensive security and adversary emulation across energy, space, OT/ICS, and critical-infrastructure systems
π€ Increasingly building autonomous agent systems: multi-agent runtimes, agentic pentest tooling, and portable Agent Skills
π Security tooling, compliance auditing, CVE research, and training infrastructure for ethical hacking
βοΈ I write up pentesting, CTFs, and security automation at d3vn0mi.com
π Professional profile at isomarakis.com Β· threat intel at hackingallthethings.com
| π | Currently working on | SIERA (AI agent orchestrator) & HackingAllTheThings (threat intel platform) |
| π― | Specializing in | Penetration Testing, Security Automation, Compliance Auditing, Agentic Systems |
| π§ | Tech Stack | Python, TypeScript, FastAPI, React / Next.js, Docker, Ansible |
| π | Active on | HackTheBox, CTF Challenges, CVE Research & Disclosure |
| π€ | Consulting for | Security Assessments & Training Programs |
| π§ SIERA |
A personal AI operations platform. A local multi-agent runtime (~18 agents, each with its own persona, scoped toolset, and skills; 26 tool plugins) coordinated behind a voice-driven Next.js 15 / React 19 heads-up display, backed by an Obsidian knowledge vault. Loopback-only, fully self-hosted. |
| π HackingAllTheThings live β |
Self-hosted cyber threat-intelligence platform aggregating 30+ open-source feeds β security news, NVD CVEs, ExploitDB / CISA KEV, dark web, MITRE ATT&CK mapping β with a live 3D attack globe. FastAPI + React across 9 Docker services, with OAuth2 SSO and RBAC. |
| πͺ | Kagami | Offline forensic-analysis & config-auditing tool running local LLMs (Ollama) over evidence against CIS/STIG/NIST/OWASP with CVSSv3 scoring β no data leaves the host |
| π | Kenbu Auditing Solution | Web-based security-audit & compliance platform β 460+ CIS benchmark checks across 8 platforms, live audit sessions, Excel reporting, GitHub OAuth SSO |
| π | ArtiForge | Cross-platform event-artifact generator for cyber-training labs β 71 Windows/Linux generators with correlated IDs, binary EVTX export, and Sigma-rule evaluation |
| π΅οΈ | AgentSmith | Autonomous pentest agent driving recon and exploitation over SSH, streaming every command and piece of evidence to a live web dashboard |
| π¦ | RAVEN EASM | External Attack Surface Management platform (Django, Celery, Redis) running 20+ recon tools with AI-powered finding correlation |
| π§© | Agent Skills | Portable SKILL.md capabilities for Claude, Codex, Cursor and other agents β published on MCP Market |
| π‘οΈ | Ryo Tenkai | RPC client for the MSF RPC server, built for security automation |
| π― | OPC UA Sniffer | Captures and dissects OPC UA traffic β credentials, read/write operations, and protocol details for OT/ICS analysis |
| π | Morgans | Generates malicious/benign ODT file sets with embedded, customizable macros for phishing payload testing |
| π | EzCME | CrackMapExec wrapper that organizes enumeration output into clean, structured files for engagement analysis |
| CVE-2026-23744 | Unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field |
| CVE-2025-2304 | Mass-assignment privilege escalation in Camaleon CMS β CVSS 9.4 |
| CVE-2026-27470 | Authenticated second-order SQL injection in ZoneMinder getNearEvents() β CVSS 8.8 |
| CVE-2016-16113 | Proof-of-concept exploit |
|
|
|
All security research and testing is conducted in authorized environments with proper permissions.



