About Me
I’m a penetration tester with more than five years of experience assessing web applications, APIs, networks, and internal and external infrastructure.
My approach is manual-first. I focus on validating real-world exploitability, identifying vulnerabilities that automated tools may miss, and separating genuine security risks from scanner noise.
Areas of Focus
- Web application penetration testing
- API penetration testing
- Internal infrastructure penetration testing
- External infrastructure penetration testing
- Network penetration testing
Testing Approach
My testing includes authentication, authorization, access control, business logic, input validation, session management, and security configuration reviews.
I use Burp Suite Professional extensively and develop Python utilities to improve testing workflows, evidence collection, and repeatability.
I work across the complete assessment lifecycle, including:
- Security testing and vulnerability validation
- Proof-of-concept development
- Technical and executive reporting
- Severity and CVSS assessment
- Remediation guidance
- Vulnerability retesting
My reports provide clear technical evidence, business impact, reproduction steps, and practical recommendations that security and engineering teams can act on.
Security Research
I was credited as the researcher for CVE-2022-2473, an authenticated stored cross-site scripting vulnerability affecting the WP-UserOnline WordPress plugin.
This website contains selected security research, certification notes, technical references, and security-related projects.
Certifications & Qualifications
- OffSec Experienced Penetration Tester — OSEP
- OffSec Certified Professional — OSCP
- OffSec Wireless Professional — OSWP
- CREST Practitioner Security Analyst — CPSA
- Hack The Box Pro Lab — Offshore
Professional Profiles
Contact
I’m open to relevant conversations involving penetration testing, offensive security, security research, and independent security assessments.
