Lead a team for defining/developing security forensic features.
Developed software agent collecting/inspecting systems/workloads for data analytics.
1. Collecting real-time network and process information from kernel
2. Generating workload forensic events based on process/system activities
3. Sandboxed software architecture to reduce attack surface
4. Secure communication over SSL/TLS with backend.
5. Automatic secure agent upgrade.
6. gccgo porting for AIX