Skip to main content
System Online · Castle Hill, NSW

Mohammad Raouf Abedini

CYBER

Research

"Seek, and ye shall find" — Matthew 7:7Independently discovering, validating, and responsibly disclosing cross-platform vulnerabilities. Authored "The Invisible Window" — 100% screen capture evasion. Motivated by reducing catastrophic risks from advanced AI.

Anthropic AI EvaluatorVulnerability ResearcherMacquarie University · Nov 2026
SYSTEM ONLINEAI SECURITY RESEARCHVULNERABILITY RESEARCHRESPONSIBLE DISCLOSURECROSS-PLATFORM EXPLOIT DEVELOPMENTLLM SECURITY EVALUATIONAI SAFETYANTHROPIC AI EVALUATORPYTHON & SYSTEMS PROGRAMMINGREDUCING CATASTROPHIC AI RISKSTHE INVISIBLE WINDOW70+ PROJECTS SHIPPEDOFFENSIVE SECURITYDUAL-USE RISK ASSESSMENTCASTLE HILL · NSW · AUSYSTEM ONLINEAI SECURITY RESEARCHVULNERABILITY RESEARCHRESPONSIBLE DISCLOSURECROSS-PLATFORM EXPLOIT DEVELOPMENTLLM SECURITY EVALUATIONAI SAFETYANTHROPIC AI EVALUATORPYTHON & SYSTEMS PROGRAMMINGREDUCING CATASTROPHIC AI RISKSTHE INVISIBLE WINDOW70+ PROJECTS SHIPPEDOFFENSIVE SECURITYDUAL-USE RISK ASSESSMENTCASTLE HILL · NSW · AU

Deployed Systems

projects

[OPS] OFFENSIVE
IEEE-FORMAT PAPER2026

Invisible Window Research

IEEE-format research paper exposing a structural vulnerability in WebRTC-based exam proctoring. 100% evasion on Windows 10/11 and macOS 14–26 using documented OS display APIs. Responsibly disclosed to vendors.

Security ResearchWindowsmacOSWebRTCResponsible DisclosurePoC
RepoCase Study
[SEC] DEFENSIVE
CONNECTED TO INVISIBLE WINDOW2026

Project Simurgh

Zero-trust integrity API connected to The Invisible Window research. Validates behavioral intent and environment integrity without relying on screen pixels, webcam frames, or invasive visual surveillance.

Integrity APIAI SafetyProctoringTelemetryNode.jsPrivacy
RepoCase Study
[SYS] ENGINEERING
LOCAL-FIRST · MCP AGENT MEMORY2026

Project Zurvan

Local-first LLM knowledge engine. Ingests any document, extracts structured knowledge (claims, concepts, entities, decisions), and exposes it to AI agents via an MCP stdio server. 183 tests passing.

PythonLLMMCPKnowledge GraphSQLiteLocal-firstAI Agents
RepoCase Study
[SEC] DEFENSIVE2024

Mehr Guard

Privacy-first offline QR & URL security scanner built with Kotlin Multiplatform. 100% offline analysis with 5 platform targets.

KMPSecurity ToolAndroidiOSDesktopWeb
Demo RepoCase Study
[SYS] ENGINEERING2026

Syllabus-Sync

AI-native Campus OS transforming university PDF syllabi into structured, agent-readable data. Full student operations suite with 503 tests across 92 files.

Next.js 16SupabaseTypeScriptAI/LLM
[SYS] ENGINEERING2024

GitSwitch

AI-powered Git client for managing multiple identities and generating semantic commits. Built with Electron and React.

ElectronReactTypeScriptAI
Repo
[SYS] ENGINEERING2026

Nexus Archive

Cyberpunk-styled personal media vault with React frontend, Litestar API, and Supabase auth. AI-assisted recommendations, encrypted takeaways, and hardened cookie-based auth.

ReactPythonLitestarSupabase

Operating Principles

Philosophy

R

RESEARCH

Independently discover, validate, and responsibly disclose vulnerabilities. Measure AI capability uplift, characterise safety boundaries, and publish reproducible findings.

  • + Vulnerability Research & Disclosure
  • + AI Safety & LLM Evaluation
  • + Dual-Use Risk Assessment
S

SECURE

Defensive applications that reduce real-world risk. Cross-platform exploit development informs better defences — offensive knowledge applied to protective systems.

  • + Cross-Platform Exploit Development
  • + Responsible Disclosure (OWASP/FIRST/CISA)
  • + Defensive Applications
THE_LAB/ active_operations

Hands-on vulnerability research and AI safety experimentation. Current work: cross-platform exploit development, AI capability uplift measurement, and safety boundary characterisation.

Vulnerability ResearchAI SafetyExploit DevelopmentResponsible Disclosure
ENTER_LAB

Technical Writing

Write-ups