tl;dr - I was frustrated by how complex cybersecurity is and built a product that looks to address common pain points during investigations by focusing on Security, Simplicity and Speed.

Who am I:
A cybersecurity professional with 9 years of experience in security operations, threat hunting, digital forensics, incident response, reverse engineering and threat intelligence
Worked for JPMorgan Chase, ExpressVPN and did contracting work for companies including Unilever
Hold various certifications, trophies, coins and medals acquired over the years from reputable competitions, challenges and organizations across the cybersecurity industry
A person who is frustrated from the overhead and complexity I’ve experienced in every place I have worked when I’ve performed investigations and cybersecurity work
What did I build:
I am a solo founder who got inspired by the “indie hacker” community and built a cybersecurity platform to address some of the pain points that I have consistently experienced throughout my career
The platform is called “Cursed Tools” as it was inspired from my experience in working with cybersecurity tools that made me feel “cursed”. It aims to provide modern, secure and fast security investigation and testing capabilities to tech users, security professionals and AI agents (soon!)
I developed the product with privacy, security and performance in mind with a focus on the user experience (UX)
At present there is no product that offers similar investigative capabilities as a service online
Complexity - Cybersecurity is really hard, even for people who work in the industry vertical. There are a lot of antiquated beliefs when it comes to securing systems. Frequently when trying to answer critical questions like “What happened?” the journey to get to an answer is riddled with hoops and hops for something that should have taken a few minutes.
Tooling Challenges - There are thousands of tools, cheat sheets and guides online that tell you what to do. You often have to install virtual machines, download antiquated versions of software and wrestle with dependencies to make them run. The whole process is closer to necromancy than to security analysis. You shouldn’t need to deploy a whole “Security Information and Event Management” (SIEM) platform or ingest data into a special tool to get you started. And forget about AI Agents or LLMs doing the work for you, as they choke when you give them large contexts or obscure proprietary formats to process.
Poor UX - Most security products suffer from a horrific user experience. Often showing you data in GUIs that resemble Excel from the 90s, you can easily end up getting lost in all of the buttons, drop downs, fields, filters and odd formats that they offer.
Growing Demands - Technology is evolving at faster rates than ever before. Organizations are still struggling to understand Cloud, SaaS, microservice architectures and modern technology stacks. Meanwhile, security programs at organizations (that can even afford them) are still struggling with observability over their tech infrastructure and access management. The demands for protecting everything have exponentially increased, but the tools, industry knowledge and support for security professionals have not caught up with them. This is expected to only grow as a challenge with the introduction of AI-generated code and products that can ship changes faster than any normal human can process.
Burnout - The never-ending barrage of investigative leads, alerts and findings that require attention historically has been exceptionally high. In most environments it leads to burnout due to the overwhelming volume of things that require our attention. And when your tech surface grows - everything becomes a spaghetti mess of connecting the dots.
Introducing “Cursed Tools” - The Security Experience platform. A B2Both solution for end users, businesses and AI agents that want better security insights. (Note: I much prefer B2ABC for Agent, Business & Consumer, but I don’t think that exists really).
What makes this product different? - At present there is no product online that offers users the option to perform analysis through the browser. Especially ones that are privacy-oriented, secure, fast and with a modern UX look and feel.
Who is it for? - Although exclusively built to address the pain points of cybersecurity professionals, it can also be used by any developer, engineer or IT technician to run diagnostics or gain rapid insights into system activity with tools that are more accessible.
How does it work? - The product is accessible through any modern browser and via API access. You can explore data and insights in its different “tools” (or modules) with or without an account. All data passing through the platform is securely encrypted and processed. Authenticated users receive end-to-end encryption features, where by design the data you submit is not accessible by the service.
What features are available right now? - The following features were developed as part of the MVP for the service:
Windows Event Log Analyzer
Anyone who's opened up Windows Event Viewer can tell you how quickly they want to close it. This module transforms raw EVTX files into key security insights in the form of charts, graphs, timelines and tables. It also offers a more modern browsing, searching and filtering experience of EVTX events, as in most cases we all just needed something closer to "grep".
Sigma Playground
Have you ever searched online for "Test Sigma online" only to stumble on Agile methodologies and "Sigma Male Test" content? You are not alone. At present there is no online platform that can help you validate your Sigma detection rules with immediate feedback. Other tools force you into tedious edit-test-deploy cycles with limited visibility, this module offers interactive rule development with instant validation and ways to run community rules across your data.
Windows Native Executable Lookup
Have you ever wondered what “kbdfi1.dll” under the System32 folder is? Do you know what “riched32.dll” is and if it belongs on any Windows system natively? Well, neither did I, until now. This module provides instant insights on core Windows executable files that come natively with different versions of Windows operating systems, service packs, versions and more.
Windows Event ID Lookup
To this day people memorize event ID codes, but the ocean of Windows event logging is much deeper for any one person to understand. This module delivers structured information about all recognized Windows Event log IDs and Providers for different operating system flavors and event log versions.
To put it simply - this was the hardest thing I’ve ever done. Everything was painful and there were no “vibes” during any of it. AI LLMs frequently fell through as they attempted to offer solutions, but ended up deleting valuable functionality or introduced critical vulnerabilities.
It took me 6 months to produce the MVP. I’ve included my GitHub commit history chart below, but unfortunately it doesn’t show the full spectrum of what it took. There were many days with early mornings and late evenings just stuck in front of a white board running through scenarios and simulations related to architectural decisions, authentication, user flows, encryption, horizontal and vertical scalability, observability, payments and so many others.
To anyone who is going through this journey or about to start it - don’t give up, it is possible. You just have to take it one day at a time. To anyone that has already gone through it - you have my utmost respect.
I have an ambitious roadmap planned, but before starting on it there is something more important - Feedback from you, your colleagues and your peers. Head over to https://cursed.tools and give it a try! All forms of feedback about the product, the UX and the idea are greatly appreciated.
If you are interested in building on top of the service, want some help with threat modeling or want to learn more about the journey - drop me a message.