This is where I write about security research and bug bounty hunting.
Most of my work is on web applications and APIs — finding, proving, and reporting security vulnerabilities — plus the reconnaissance that surfaces the endpoints worth testing in the first place. I have a soft spot for financial-services platforms, where a decade of prior work in IT and banking systems gives me useful context.
What you’ll find here over time:
- Writeups of methodology and (where disclosure allows) findings.
- Recon notes — how I map attack surface on wide-scope programs.
- Testing patterns — recurring classes of web vulnerabilities and how to find them.
More to come. If you want to reach me, the links are in the header and on the about page.