Howdy, I'm Chris Partridge!

By day, I'm lucky enough to lead a high-caliber cybersecurity engineering team at Amazon, and I occasionally teach cybersecurity at RIT to the next generation of geeks trying to keep people safe.

By night, I'm an avid cat dad, solarpunk, open source developer, home cook, and tinkerer. You may see me around the internet as tweedge, a nickname based on my last name :)

Welcome to my little corner of the internet! It has ⋆˙⟡ stuff ✧˖°.

Recent Posts

I'm a yapper, and I'm working on blogging more often about the things I build, get up to, have opinions on, etc. Most of my yapping is about cybersecurity and technology, and recently I've written:

- Seven months of watching people typo NLTK on PyPI
A long time ago, I uploaded a benign typosquatting package to PyPI to measure how often people accidentally type 'ntlk' instead of 'nltk'. Over seven months, this amassed 28,839 installs (not just downloads) from 10,938 unique IPs - including from corporate and government networks. Read more

- It's tax season! You can tell by the malware campaigns impersonating the IRS
A quick dive into a hilariously unconvincing, malware-laden email that I received which is impersonating the IRS. I love the self-assessment model for taxes in the USA, the billion-dollar companies that profit off taxes being confusing and difficult, and hundreds of millions of dollars spent in lobbying to keep it that way. It's great for everyone and has only positive network effects. This is sarcasm. Read more

But if you're looking for something specific, there are a lot more posts in the archive.

Recent Data

I believe that information should be free, and I host ~20TB of data I find interesting or specifically want to help preserve, mostly from Academic Torrents. In addition, I release data from my projects and data which has been passed to me for release via BitTorrent, currently totalling 3.4GB. My recent releases are:

Archival Copy of "RU-OK?" Research from 2022
During the start of Russia's full-scale invasion of Ukraine in 2022, I measured the uptime of web services being targeted with attacks by the Ukrainian "IT ARMY" hacktivist Telegram group, attempting to see how effective the DDoS attacks were on the targeted websites. Even in 2026 I get the occasional nastygram and takedown request, so here's a censorship-resistant archival copy distributed via BitTorrent.

And just like my posts, if you're looking for more, check my data page listing everything I've published.

Recent Docs

Alongside 'posts' - which are point in time - I also write the occasional document which is kept up-to-date in place. Today there's only one of these, but it's a very important one to me:

And once I add more of these, the dedicated page listing my docs will get a lot more interesting.

Projects

Last but not least, you can see a few things I've built and put on GitHub, roughly in order of what other people found useful:

  • springcore-0day-en - everything I needed to understand Spring4Shell - translated source materials, an exploit, links to demo apps, and more
  • emerging-threats-pihole - blocks malware on your network through Pi-Hole, using threat intelligence extracted from Emerging Threats rulesets
  • unishox2-py3 - Unicode-friendly string compression via Unishox2, packaged for Python
  • ru-ok - uptime measurements of Russian internet properties targeted by Ukraine's IT ARMY during the 2022 invasion

Thank you for visiting! If you scrolled down this far, you might want to keep in touch or ask me about something. I'm most often on Mastodon recreationally, but you can also find me on Bluesky. More ways to contact me are also listed on my contact page.

Much love,

tweedge <3