Lead Penetration Tester, learning in public. I think like an adversary, document like a consultant.
My expertise lies in conducting targeted cyber security assessments across various environments - web applications, APIs, network infrastructure, Active Directory, cloud, AI and more. I focus on realistic, goal-driven testing rather than checkbox scanning.
I combine automation with manual tradecraft to find complex issues, validate real risk, and help teams harden their environments instead of chasing noise. The deliverable that matters is a clear report a developer or defender can act on the same week.
Never give up. Never back down - constantly learning, constantly breaking, constantly improving.
I map my work to recognised industry standards so findings connect directly to risk and controls: the OWASP Testing Guide, MITRE ATT&CK, CWE, SANS Top 25 and CIS Benchmarks. My priorities are enumeration depth over speed, chaining weaknesses into real compromise paths, and reporting that's genuinely actionable.
Where my offensive work maps across the ATT&CK Enterprise matrix - breadth from reconnaissance through to impact. Hover any technique for its ID and coverage level.
Deepening my testing methodology and hands-on offensive skills.
Blogs, labs, tools and methodologies, including a new Threats & Exploits series.
Digging into how models actually work and how they fail, with a focus on practical, hands-on attacks on LLM apps.
A working selection - tools serve the method, not the other way around.