I build practical tooling for authorized security research: web application security, recon, validation, and low-noise automation.
- Web application security — attack surface, request/response behavior, bug bounty
- Security automation — repeatable recon and verification
- Research tooling — less noise, evidence attached to every finding
- Open source — focused fixes with regression tests
Daily environment: Kali Linux / WSL · Burp Suite · Nuclei · Nmap · ProjectDiscovery tooling
|
Fail-closed, evidence-based HTTP request minimizer for authorized security research. |
Low-noise active scanner for CORS, CSRF, header injection, cache poisoning, and content-spoofing leads. |
Evidence over assumptions: reproduce first, understand why, then verify.
Map the surface → Form a hypothesis → Reproduce → Validate → Keep the evidence
Authorized security research only.




