Penetration Tester · Red Teamer · Offensive Security Practitioner
I focus on offensive security with a practical, hands-on mindset. My work is shaped around careful enumeration, realistic attack paths, clear documentation, and building small tools that make security testing faster.
My main areas of interest are Active Directory security, web application testing, internal pentesting, privilege escalation, lateral movement, and bug bounty recon workflows.
I like turning repeated manual work into simple tools, labs, and notes that can be reused in real assessments.
Active Directory Security · Web Application Security · Internal Pentesting
Privilege Escalation · Lateral Movement · Bug Bounty Recon
Security Tooling · Lab Building · Practical Research
| Project | Description | Stack |
|---|---|---|
| palm | Bug bounty subdomain recon pre-filter for live and takeover checks. | Go |
| montana-framework | Searchsploit-like local exploit search tool for Kali/Linux. | Go |
| flask-ssti-lab | Deliberately vulnerable Flask SSTI lab for local cybersecurity training. | Flask |
| nhc | Hash analysis and cracking utility for lab workflows. | Python |
| SFounder | Webshell discovery helper for authorized review scenarios. | Python |
- I prefer realistic scenarios over checklist-only testing.
- I care about clean notes, reproducible findings, and practical impact.
- I build small tools when a workflow becomes repetitive.
- I use labs to understand techniques before applying them in authorized environments.
- I keep the line clear: only test systems I own or have permission to assess.
Offensive security is not just finding weaknesses. It is understanding systems deeply enough to explain risk clearly.