About
Reverse engineering & web security research.
I'm a security researcher focused on two disciplines that reinforce each other: reverse engineering and web application security. The RE work is about taking software apart — static and dynamic analysis of binaries and closed systems — to recover behavior, map attack surface, and understand precisely how something breaks. The web work applies that same mindset to modern applications and APIs, hunting authentication, access-control, business-logic, and injection flaws.
Whether a finding comes from a research target or a bug-bounty program, I handle it through coordinated disclosure: reproduce it reliably, quantify the real-world impact, and give the affected team the context they need to ship a durable fix — not just a patch. Write-ups get published here once issues are resolved and cleared for public release.
Focus areas
Reverse engineering
Static and dynamic binary analysis, unpacking, and recovering undocumented behavior to map attack surface.
Web & application security
Assessing web apps and APIs for auth, access-control, logic, and injection vulnerabilities.
Vulnerability research
Discovering, reproducing, and weaponizing bugs into reliable proof-of-concept exploits.
Coordinated disclosure
Working with vendors and bug-bounty programs to get issues fixed and safely published.