Offensive Security · Application Security · Software Engineering
Software engineer with 3+ years of professional experience building web, mobile, and SaaS products. I focus on offensive security and application security, combining an attacker's perspective with practical knowledge of authentication, authorization, APIs, multi-tenant data isolation, and production infrastructure.
I build security tooling and reproducible proof-of-concepts for authorized research and lab environments.
| Project | Focus |
|---|---|
| CVE-2026-4480 — Samba print command injection | Unauthenticated command injection through Samba's %J print job substitution |
| CVE-2026-3888 — snap-confine privilege escalation | Local privilege escalation through a race condition and loader hijacking |
| AD CS ESC1 template cloning | Active Directory Certificate Services privilege escalation |
| Gitea/Gogs symlink to RCE | .git/config poisoning through repository-content APIs |
| PyYAML to AWS CodeBuild escape | Unsafe deserialization chained with a privileged container escape |
| SOAP/WCF XXE file disclosure | Out-of-band XXE exploitation and server-side file disclosure |
| Project | Description |
|---|---|
| Vandal | Web security scanner for reflected XSS, SQL injection, security headers, subdomain discovery, and historical URL collection |
| Luna | Modular REST API security scanner covering IDOR, authentication, SQL injection, XSS, HTTPS, and structured JSON reporting |
| Astral Sniffer | Packet capture and traffic analysis with protocol filters, PCAP export, and CSV/JSON statistics |
| Good Luck | Multithreaded SYN, TCP, and UDP port scanner with banner grabbing and JSON output |
| Pentest Reports | Web and API penetration-testing report templates using OWASP, PTES, CWE, and CVSS v3.1 |
| Security | Web and API security, vulnerability research, exploitation, privilege escalation, network analysis, DFIR |
| Engineering | Authentication and authorization, REST APIs, RBAC, Row Level Security, multi-tenant systems, secure SDLC |
| Languages | Python, Bash, Go, JavaScript/TypeScript, Kotlin, Swift |
| Infrastructure | Docker, PostgreSQL, Redis, Supabase, Cloudflare, Vercel, Nginx |
- Vulnex — Cybersecurity SaaS for breach exposure, compromised credentials, and typosquatting monitoring.
- Vandal Health — Multi-tenant healthcare SaaS using RBAC, Row Level Security, REST APIs, and containerized deployment.
- Healthcare interoperability API (private repository) — OAuth2 Client Credentials, JWT, tenant isolation, Redis rate limiting, and security tests for exchanging sensitive clinical data.
- Fix! — Native iOS and Android applications with Firebase authentication, APNs/FCM, Mercado Pago, and production store releases.
- Lightmoon — Social platform with Google OAuth, profiles, posts, comments, and reactions.
- RACE.COM — Android application communicating with motorsport scales through Bluetooth Low Energy.
Most professional source code is private due to client confidentiality.
Hack The Box: Hacker rank · Level 53 (Professional)
Progress: 35 machines · 41 challenges · 12 Sherlocks
Selected Hack The Box work
- Hard: Nimbus, Snapped, Ghostlink, Checkpoint
- Medium: Abducted, DanglingTree, Bedside, Layover, MakeSense, SmartHire, Principal, FireFlow, DevHub, Blurry
- Easy: Cohort, Touch, Management, TwoMillion, Kobold, Silentium, Orion, Nexus, Paperwork, Enigma, Connected, Reactor, Bashed, Irked, PermX, Networked, Luanne, Cap, Spectra, Lame
- Web: ReactOOPS, OpenSecret, Space Explorer, Sp00ky Theme, WayWitch, Armaxis, OnlyHacks, Evaluative, Spookifier, Flag Command, SpookyPass
- DFIR/Forensics: Primed for Action; UFO-1, Operation Blackout 2025: Phantom Check, CrownJewel-1/2, Reaper, Noxious, Campfire-1/2, Dream Job-1, BFT, Unit42, Brutus
- Additional work across crypto, reversing, OSINT, hardware, satellite, and quantum challenges
Additional practical training through Hack4u in ethical hacking, offensive Python, Linux administration, and professional Linux environments. English: B1 conversational, B2 reading/writing.
Security tools and proof-of-concepts in this profile are intended exclusively for authorized testing, research, and educational environments.