This is your work, valued

Austin, Texas

Ryan MacDonald

Elite
@rfxn

Offensive Thinking. Defensive Engineering | Linux Security & Open Source

linux-malware-detect. Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

1.5k

advanced-policy-firewall. iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support

112

brute-force-detection. Brute force detection with exponential-decay pressure scoring, 57 service rules, 8 firewall backends, GeoIP enrichment, and multi-channel alerting

29

process-resource-monitoring. Per-process CPU, memory, and runtime limiter for Linux with rules-based enforcement, auto-kill, parent tree termination, and syslog alerting

15

rdf. Governance-driven AI development framework -- convention enforcement, quality gates, and domain expertise for Claude Code, Gemini CLI, and Codex

15

cpanel-sessionscribe. Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.

13

rfxn-defense. Responsive defense layer for Linux; ships kernel-LPE mitigations as 0days land. Coverage: Copy Fail family (cf1, cf2, Dirty Frag, Fragnesia, PinTheft, DirtyDecrypt) + FD-theft (ssh-keysign-pwn). EL7/8/9/10.

13

blacklight. The future is Mythos-class agents that take vuln-to-exploits from days to hours, Linux defense is still stuck at human speed. Blacklight is the agentic counter-measure: a skills-native Managed Agent that directs OSS defensive primitives at the speed of the attack. GPL v2. (Opus 4.7 hackathon)

12

system-integrity-monitor. System and service monitor for Linux with auto-restart, socket and process verification, and event alerting for 25+ services

10

scripts. Shell

4

talks. Conference talks, presentations, and technical decks by R-fx Networks

4

lynis. Lynis - Security auditing tool and assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Works on Linux, Mac OS, and Unix based systems, with installation being optional.

3

ansible-role-kmod-tpe. ansible role for install/setup of Trusted Path Execution Linux Kernel Module

3

system-tuner. Apache capacity planner with PHP-aware MPM tuning, tiered profiles, error log health scanning, cPanel integration, and JSON output

3

zenbot. Zenbot is a command-line cryptocurrency trading bot using Node.js and MongoDB.

1

rules. Repository of yara rules

1

Open-Source-YARA-rules. YARA Rules I come across on the internet

1

magento-malware-collection. Classes of malware found in the wild on Magento sites

1

elog_lib. Shared structured event logging library for rfxn projects

1

tlog_lib. Bash library for incremental log reading with cursor tracking, rotation detection, multi-format compression, atomic writes, and journal fallback

1

pkg_lib. Shared Bash library for unified packaging, install, and uninstall across rfxn projects

1

alert_lib. Shared Bash library for multi-channel transactional alerting

1

batsman. BATS test infrastructure with 9-OS Docker matrix, parallel orchestration, and reusable GitHub Actions CI workflow

1

geoip_lib. Shared GeoIP metadata library for Bash — country names, continent mapping, CIDR downloads

1

csm_lib. ConfigServer Migration Library: Bash library for detecting and migrating CSF/LFD/CXS to APF/BFD/LMD

1