01. about
I'm Michelle Duell, a security researcher and intelligence professional with an active [REDACTED] clearance. Right now I'm an AI safety red team fellow, running adversarial testing against frontier AI systems. Behind that is eight years of operational targeting and multi-source intelligence work, a 16-report threat intelligence series, and podium finishes in national cybersecurity competitions. I'm looking for roles in threat hunting, threat intelligence, incident response, SOC, detection engineering, and AI red teaming.
Reverse engineering is where I do my deepest work. I trace suspicious samples through a decompiler to understand what they do and why, working static binary analysis in Ghidra and taking mobile apps apart with adb, apktool, and smali. I turned that methodology into a conference talk accepted from more than 1,500 proposals for the WiCyS 2026 National Conference, where I co-presented static binary analysis from novice to professional level.
I build AI tooling as much as I use it. At the KC7 Foundation I volunteer as an AI Workflow Engineer and Threat Content Analyst, where I contributed to published threat scenarios and built a pipeline of more than 40 coordinated LLM agents that cut scenario production from roughly 21 days to about 3 hours. In my own lab I wired Ghidra, radare2, jadx, dnspy, and x64dbg into LLM-assisted reverse engineering workflows through MCP.
As a SANS Cyber Academy Scholar and GIAC Advisory Board member, I've earned GCIH (98%), GSEC (95%), and GFACT (100%) certifications, along with a Trusted AI Safety Expert (TAISE) certification from the Cloud Security Alliance, and I'm currently working toward the HTB Certified Penetration Testing Specialist (CPTS). I've put those skills to the test in competition, placing 1st in the Tenable x WiCyS CTF, 1st Overall and 1st Industry Professional at the WiCyS 2026 Conference CTF, 1st in the WiCyS Cyber Quest Tournament, 2nd in the SANS Women's History Month BootUp CTF, 2nd in the WiCyS x Target Cyber Defense Challenge, and earning Runner-Up Most Creative Report and 5th place in the SANS Holiday Hack Challenge.
Outside of competitions, my homelab and independent research keep the work hands-on. The GCP honeypot is complete, 96 million events across 28 days documented in a 16-report research series. AeroLab v2 is the current focus: a full rebuild across two physical Proxmox nodes with five segmented networks and a detection stack built around Elastic SIEM 9.x, Velociraptor for endpoint forensics, and MITRE Caldera for ATT&CK-mapped adversary emulation against a Windows Server 2022 domain controller, running identity-based attacks including Kerberoasting, AS-REP roasting, Pass-the-Hash, and DCSync, then capturing and analyzing the resulting attack telemetry in Elastic SIEM. The lab also has an AI security side: a local LLM stack running open-weight Mistral models on Ollama, with tool use enabled, a retrieval pipeline built on local embeddings, and a QLoRA voice fine-tune trained in Unsloth on my own writeups. I wrote llm-redteam-mcp, an MCP tool that runs offensive tests against those models, probing prompt handling, tool use, and retrieval behavior in a fully controlled environment. I'm also working through the Cisco CCNA 200-301 curriculum via the NetworkChuck Summer of CCNA to sharpen the networking fundamentals that sit underneath all of it.
Currently open to cybersecurity opportunities, collaboration on security research, and speaking engagements.
02. achievements
Competitive Achievements
Tenable x WiCyS Exposure Quest CTF
1st place finish in the Tenable x AWS Capture the Flag: Exposure Quest Edition, hosted by Women in CyberSecurity (WiCyS). Competed across three days navigating Tenable's Nessus platform and cloud dashboards, hunting flags through scan data, plugin IDs, audit findings, asset data, and vulnerability reports with no prior platform experience.
WiCyS 2026 Conference CTF
1st place Industry Professional and 1st place Overall in the NCL-hosted CTF at the WiCyS 2026 Conference in Washington, DC. Competed across OSINT, password cracking, log analysis, network traffic analysis, cryptography, web application exploitation, and forensics challenges.
WiCyS Cyber Quest Tournament
1st place finish out of ~325 competitors in the Women in CyberSecurity (WiCyS) Cyber Quest Tournament powered by SANS Institute Cyber Ranges. Competed across network forensics, web exploitation, SIEM analysis, assembly programming, and multi-stage exploitation challenges.
USCC East Cyber Camp
Team captain of the 1st place team at the US Cyber Challenge East Cyber Camp, advancing to the Cyber Bowl and on to the national round in Washington, DC. Competed across reverse engineering, OSINT, web application exploitation, binary exploitation, cryptography, and hash cracking.
SANS Women's History Month BootUp CTF
2nd place finish in a free, 72-hour global CTF hosted by SANS Institute, open to beginner and intermediate competitors worldwide. Competed across web exploitation, network forensics, pwn, log analysis, and password cracking.
SANS NetWars North America
2nd place team finish at SANS NetWars North America, a hands-on tournament run on SANS cyber ranges. Competed across reverse engineering, OSINT, web application exploitation, binary exploitation, cryptography, and hash cracking.
Elastic Security CTF
2nd place individual finish in the Elastic Security CTF. Worked hands-on in the Elastic platform, hunting answers through log analysis with KQL and ES|QL queries.
SANS Holiday Hack Challenge
5th place finish solving all 26 challenges and Runner-Up for Most Creative Report. Built custom technical writeup webpage with interactive elements and comprehensive documentation covering router exploitation, web application attacks, privilege escalation, cloud security misconfigurations, and protocol analysis.
Target x WiCyS Cyber Defense Challenge
2nd place overall finish in national cyber defense competition. Successfully defended infrastructure against red team operations while maintaining critical services.
Speaking Engagements
"Reverse Engineering with Ghidra for DNS Exfiltration"
February 2026WiCyS San Diego Virtual Speaker Series
Co-presenting 45-minute technical session covering novice to professional reverse engineering methodologies using Ghidra for static binary analysis.
"Reverse Engineering with Ghidra for DNS Exfiltration"
March 2026WiCyS 2026 Conference | Washington, DC
Co-presenting 45-minute technical session covering novice to professional reverse engineering methodologies using Ghidra for static binary analysis.
Technical Writing
Author of technical reports and analysis documenting CTF challenge solutions, honeypot deployment findings, blockchain security research, and homelab infrastructure. Published 35+ articles, including a 16-report threat intelligence series, at aerobytes.io/writeups
03. certifications & training
$ cat active_certifications.txt
- → SANS Cyber Academy Scholar
- → Certified Penetration Testing Specialist (CPTS) | In Progress
- → Trusted AI Safety Expert (TAISE) | March 2026
- → GIAC Certified Incident Handler (GCIH) | February 2026
- → GIAC Security Essentials (GSEC) | December 2025
- → GIAC Foundational Cybersecurity Technologies (GFACT) | October 2025
- → ISC2 Certified in Cybersecurity (CC) | June 2025
- → Google Cybersecurity Professional Certificate | 2025
- → Google IT Support Professional Certificate | 2025
- → Google AI Essentials | 2025
04. education
Undergraduate Certificate, Computers and Networking
2022American Military University
Associate of Applied Science, Intelligence Operations
2019Cochise College
Master of Music Education
2010Lamar University
Bachelor of Music Performance
2007Lamar University
05. professional affiliations
06. professional experience
AI Safety Red Team Fellow
Handshake AI | Remote (Contract)
- Conduct structured adversarial testing of large language models, probing model behavior against safety policies and documenting reproducible findings
- Apply offensive security methodology and threat intelligence tradecraft to identify failure modes in frontier AI systems
AI Workflow Engineer & Threat Content Analyst (Volunteer)
KC7 Foundation | Remote
- Designed and built an agentic LLM pipeline of 40+ specialized agents, cutting threat scenario production time from roughly three weeks to roughly three hours
- Contributed to 6+ published games on KC7's free cybersecurity education platform, authoring threat scenarios and investigative workflows
- Review threat scenarios and investigative workflows for technical accuracy, validating that attacker techniques reflect realistic TTPs
[REDACTED] Intelligence Analyst
U.S. Army Reserve | [REDACTED] Clearance
- Conduct intelligence analysis operations supporting [REDACTED] missions
- Lead cross-functional teams in multi-source intelligence production
- Author detailed intelligence reports and briefings for senior leadership requiring clear technical writing and complex information synthesis
- Analyze imagery and geospatial data using pattern recognition techniques directly applicable to network traffic analysis and threat hunting
- Apply intelligence cycle methodologies (collection, analysis, dissemination) mirroring the threat intelligence lifecycle
- Identify adversary tactics, techniques, and procedures (TTPs) and correlate indicators across multiple data sources
OSINT Researcher (Volunteer)
National Geospatial-Intelligence Agency GEMINI Program
- Maintain and enhance open-source intelligence maps using research approaches aligned with cyber threat intelligence collection and OSINT reconnaissance
Band Director
Nederland Independent School District | Nederland, TX
- Led highly successful band program of approximately 500 students, earning multiple regional and state recognitions for performance excellence
- Developed curriculum, managed student performances, and coordinated community outreach programs
- Applied strong leadership, organizational skills, and cross-functional collaboration with administrators, parents, and community stakeholders
07. legacy systems
Before pivoting to cybersecurity, I spent over a decade as a professional musician. Mastering complex systems is kind of my thing.
Professional Orchestral & Jazz Performance
- → Assistant Principal Clarinet in three professional symphonies
- → Multi-woodwind specialist in professional musical pit orchestras
- → Jazz saxophonist in big band ensembles
Music Education & Leadership
- → Graduate Assistant: Conducted university concert band
- → Rebuilt university marching band program from the ground up
- → Assistant Band Director managing 500+ student program
- → M.M. in Music Education, B.M. in Clarinet Performance
$ echo "Fun fact: I was a Blockbuster Video manager in college. Yes, I'm that old."