About Me

I’m a penetration tester with more than five years of experience assessing web applications, APIs, networks, and internal and external infrastructure.

My approach is manual-first. I focus on validating real-world exploitability, identifying vulnerabilities that automated tools may miss, and separating genuine security risks from scanner noise.

Areas of Focus

  • Web application penetration testing
  • API penetration testing
  • Internal infrastructure penetration testing
  • External infrastructure penetration testing
  • Network penetration testing

Testing Approach

My testing includes authentication, authorization, access control, business logic, input validation, session management, and security configuration reviews.

I use Burp Suite Professional extensively and develop Python utilities to improve testing workflows, evidence collection, and repeatability.

I work across the complete assessment lifecycle, including:

  • Security testing and vulnerability validation
  • Proof-of-concept development
  • Technical and executive reporting
  • Severity and CVSS assessment
  • Remediation guidance
  • Vulnerability retesting

My reports provide clear technical evidence, business impact, reproduction steps, and practical recommendations that security and engineering teams can act on.

Security Research

I was credited as the researcher for CVE-2022-2473, an authenticated stored cross-site scripting vulnerability affecting the WP-UserOnline WordPress plugin.

This website contains selected security research, certification notes, technical references, and security-related projects.

Certifications & Qualifications

  • OffSec Experienced Penetration Tester — OSEP
  • OffSec Certified Professional — OSCP
  • OffSec Wireless Professional — OSWP
  • CREST Practitioner Security Analyst — CPSA
  • Hack The Box Pro Lab — Offshore
OffSec Experienced Penetration Tester — OSEP OffSec Certified Professional — OSCP OffSec Wireless Professional — OSWP

Professional Profiles

Contact

I’m open to relevant conversations involving penetration testing, offensive security, security research, and independent security assessments.