handle: CatFoxVoyager # Jay D.
role: Cybersecurity consultant — vulnerability management
based: Québec, Canada ⚜️ 🇨🇦
field: B.Sc. Cybersecurity
background: 15+ years IT infrastructure → SOC analyst → offensive & defensive security
focus: [ vulnerability management, applied AI / LLMs, DFIR, OSINT ]
belief: "The future of cyber defense runs on artificial intelligence."I spend my days helping organizations turn messy vulnerability data into decisions, and my nights building open-source tools that put AI to work on real security and civic problems.
| Project | What it is | Stack |
|---|---|---|
MermaidStudio · repo |
Open-source Mermaid diagram editor with an AI assistant. AI runs fully in your browser via WebGPU (Qwen3.5) — no server, no data leaving the tab. Version history, templates, diffs, export. Now on Google Play (Android, v2.1.0 — 26 shapes, offline-first). | TypeScript · WebGPU (WebLLM/Qwen3.5) · Capacitor Android · Kotlin |
| Carte citoyenne du radon | A community radon-risk map for Canada. Type an address, get the risk. Citizens can add their own anonymous test results to enrich the map for their neighbourhood, on top of Health Canada open data. | TypeScript · MapLibre · Protomaps |
CVE → MITRE ATT&CK · write-up |
Multi-label ModernBERT-Large classifier that maps raw CVE descriptions to all 691 ATT&CK techniques & sub-techniques. Built the dataset from scratch (real + synthetic, LLM-generated then audited) to beat class imbalance. Dataset published on 🤗. | Python · PyTorch · Transformers · Optuna |
| LLM-driven pentest tooling | Workflow orchestration, model evaluation and automated report generation for offensive security engagements. | Python · local + hosted LLMs |
| bombvault | Unraid backup & full disaster recovery — Docker containers, KVM VMs, flash config — encrypted, off-site, restic-powered. | Go |
CVE-TO-MITRE — 20 000 vulnerability descriptions (10k real CVEs + 10k synthetic) labelled with MITRE ATT&CK technique IDs, multi-label, MIT licensed. Released so others can train their own triage models instead of starting from the ~2 000 public examples I had to work with.
real_10k.jsonl 10 000 real CVE descriptions → ["T1078", "T1203", ...]
synth_10k.jsonl 10 000 synthetic descriptions → rare-technique coverage
attaquemitre2.csv ATT&CK reference (id, name, description, platforms)
[▓▓▓▓▓▓▓▓░░] shipping MermaidStudio 2.1.0 on Google Play
[▓▓▓▓▓▓▓▓▓░] shipping features on carte-radon.ca
[▓▓▓▓▓▓▓░░░] smaller, faster in-browser models for MermaidStudio
[▓▓▓▓▓░░░░░] automating vulnerability triage with LLM agents
[▓▓▓░░░░░░░] digital forensics & OSINT rabbit holes
- 🧠 Automatiser le mapping CVE → MITRE ATT&CK avec BERT : dataset, biais et pièges — three months, one RTX 3090, and every trap I fell into: temporal bias, class imbalance, distribution shift.
- 📝 Fine-tuner un LLM de 0.8B pour générer des diagrammes Mermaid dans le navigateur — how the MermaidStudio model was trained, quantized and shipped to WebAssembly.
- 🎓 Mentor for students curious about IT and cybersecurity careers, since 2009.
- 🔐 20+ certifications, from Cisco CCNA to EC-Council Digital Forensics Essentials.

