
Tomer Bar
Over a decade of security research and engineering channeled into securing emerging threat landscapes
Open Source
EDR-evading password hash dumper for macOS
Obsidian brain for smart contract auditing
JXA-based macOS persistency for EDR bypass security testing
AI agent instructions for security audits
A static analysis tool for rust, anchor, stylus, and solidity smart contracts
Security scanner and CI/CD guardrails for AI skills
Analysis and real-time monitoring for Safe{wallet} multisigs
Static analysis for Solidity smart contracts
EDR-evading password hash dumper for macOS
Obsidian brain for smart contract auditing
JXA-based macOS persistency for EDR bypass security testing
AI agent instructions for security audits
A static analysis tool for rust, anchor, stylus, and solidity smart contracts
Security scanner and CI/CD guardrails for AI skills
Analysis and real-time monitoring for Safe{wallet} multisigs
Static analysis for Solidity smart contracts
Shared Workflows
Audits
Majority of my work in the past decade of breaking and fixing things across every layer of the stack, is under NDA agreements and can't be ethically shared.
Long-Form Security Research
Cloud Security
Development & Engineering
Offensive Security
Defensive & Response
Training & Workshops
CVEs
Research & Talks
EDR-Evasive MacOS Hash Dumping in 2026
Here's How Your Devs Should Sandbox Agents
8 Agentic Harness Engineering Patterns You Should Know
Radar: Static Analysis of Smart Contracts in the era of AI
Azure AD Privilege Escalation through Auto Assignment Policies
Offensively Navigating Azure
Evilginx2 - Modern Day Phishing vs 2FA Protections
Hooking with Frida


