Matthew Green

Sydney, New South Wales, Australia
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Matthew Green is a Sydney-based security professional with 18 years in the industry and a decade focused on digital forensics, incident response, and detection engineering. He blends hands-on DFIR skills with practical tooling experience, contributing to prominent open-source projects like Velociraptor and the Kansa PowerShell framework to improve malware detection and data collection. His work includes implementing artifacts and analysis functions for a wide range of threats (Cobalt Strike, Emotet, Ursnif, etc.) and extending frameworks to surface detailed Sysmon and WMI telemetry. Known as a "DFIR / Detection guy" in his GitHub bio, he excels at turning investigative ideas into reproducible code that accelerates response. Quietly pragmatic, he pairs deep technical knowledge with an operator’s mindset—building detections that investigators actually use.
code10 years of coding experience
github-logo-circle

Github Skills (12)

it-security10
powershell10
go10
incident-response10
computer-forensics10
sys10
yara10
sec10
wmi10
security10
crypto9
python4

Programming languages (14)

PowerShellMDXC#C++CRustMakefileGo

Github contributions (5)

github-logo-circle
Velocidex/velociraptor

Jul 2019 - Jan 2023

Digging Deeper....
Role in this project:
userSecurity Engineer
Contributions:33 reviews, 154 commits, 289 PRs in 3 years 7 months
Contributions summary:Matthew primarily contributed to the development of security-related artifacts and functionalities within the Velociraptor project, a digital forensics and incident response framework. They implemented and refined artifacts for detecting malware (CobaltStrike, RedLeaves, Himawari, Lavender, Armadill, zark20rk, Ursnif, Emotet, SmokeLoader, Datper, PlugX, Ramnit) and creating functions for crypto operations (xor and rc4). These contributions included integrating new detection capabilities, enhancing existing analysis methods, and adding support for Cobalt Strike beacon configuration analysis.
diggingpythonincident-responseendpoint-securitydeeper
davehull/Kansa

Dec 2016 - Dec 2017

A Powershell incident response framework
Role in this project:
userSecurity Engineer
Contributions:5 commits, 6 PRs, 1 comment in 1 year
Contributions summary:Matthew primarily contributed to the Kansa framework, focusing on the collection and analysis of security-relevant data. The commits involved modifying PowerShell scripts to gather information about WMI event consumers, filters, and bindings, along with Sysmon event data (process and network connections). These changes suggest an effort to enhance the framework's capabilities for incident response and security analysis.
incident-responsepowershell
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial