I sit at the intersection of Software Development and Information Security. I am passionate about not only breaking systems to make them stronger but also contributing code to fix the vulnerabilities I discover. My philosophy is full-cycle security: find it, fix it, ship it.
I am an active contributor to the open-source community, focusing on security tools and large-scale platforms.
- The Highlight: I discovered a security vulnerability within the GhostCMS platform.
- The Fix: Rather than just reporting it, I authored the patch to fix my own CVE findings, ensuring the ecosystem remained secure for thousands of users.
- Top contributor to CloudGoat, the leading "Vulnerable by Design" AWS deployment tool.
- Helped create scenarios that allow security professionals to hone their cloud exploitation skills in a safe environment.
- Role: Module Developer
- Expanded the capabilities of Pacu, the standard open-source tool for offensive AWS security.
- Contribution: Authored and merged multiple new modules, allowing researchers to test new attack vectors and identify misconfigurations in cloud environments.
Beyond contributing to major frameworks, I maintain a collection of custom tools and scripts tailored for:
- Red Teaming Operations
- Penetration Testing Automation
- Security Research & Reconnaissance
Check out my repositories below to see the specific scripts I use to automate exploitation and streamline security assessments.