$ cat about.md
About
Kuniyoshi Noguchi
野口 晋義
KuniNogu
AI Security, Vulnerability Research & Detection Engineering
I am Kuniyoshi Noguchi (KuniNogu), a cybersecurity engineer working across AI security, vulnerability research, security operations, incident response, threat hunting, and detection engineering.
My professional work includes investigating enterprise incidents with Microsoft Sentinel, Defender XDR, Splunk, KQL, and endpoint, identity, network, cloud, and firewall telemetry. I turn investigation findings into reusable detections, hunting hypotheses, workbooks, operational procedures, and security recommendations.
Alongside defensive engineering, I research trust boundaries in AI agents, MCP servers, plugins, callbacks, and delegated authorization. Public credits include Splunk MCP Server, Apache Struts, Redmine, Drupal AI / AI Agents, and @fastify/http-proxy. Each entry in Advisories links to the vendor's or maintainer's primary record.
I do not stop at finding a flaw. I reproduce it safely, coordinate disclosure, review the remediation, and translate the root cause into detection and incident-response guidance. This site is the canonical record connecting my offensive research to practical defensive outcomes.
# Areas of expertise
- AI Application Security
- AI Plugin Security
- MCP / MCP Server Security
- Tool Integration Security
- AI Agent Security
- Authorization Bypass
- Trust Boundary Analysis
- Callback / Webhook Security
- Responsible Disclosure
- Detection Engineering
- Microsoft Sentinel / KQL
- SOC
- DFIR
- Vulnerability Research
# Disclosure stance
I follow coordinated vulnerability disclosure. I report privately, give vendors reasonable time to remediate, confirm the fix, and only then publish an analysis written to help defenders — never to arm attackers.
# Off the clock
- 🍜 Hunting for good ramen
- 🐈 Cat person
- 🚩 CTFs on weekends
- ☕ Third coffee by noon