INDEPENDENT SECURITY CONSULTING

Freelance
Penetration Tester
& Security Researcher.

Helping businesses identify exploitable vulnerabilities in web, mobile, and API applications before attackers do.

Authorized testing. Actionable findings. Clear reporting.
ASSESSMENT FOCUS[ MANUAL FIRST ]
SECURITY
BY UNDERSTANDING
WEB API MOBILE
Explore the attack surface.
Understand the business impact.
DISCOVER THE APPROACH
+ Web Security+ Mobile Security+ API Security+ OWASP Top 10+ Business Logic+ Bug Bounty
01 / SERVICES

Built around your attack surface.

Focused assessments that connect technical weaknesses to the risks your business actually faces.

01

Web application pentesting

Manual assessment of your application, from its first login to its most sensitive workflows.

Explore assessment scope
OWASP Top 10AuthenticationAuthorizationIDOR / BOLASession managementInjectionFile uploadsServer-side vulnerabilitiesAccess-control bypassBusiness logic
02

API security testing

Understand how your APIs behave when requests move outside the intended application flow.

Explore assessment scope
REST APIsAuthenticationJWTBOLA / IDORFunction-level authorizationRate limitsMass assignmentSensitive data exposureAPI business logic
03

Mobile application pentesting

Assess the connections between the mobile client, the device, and the services behind it.

Explore assessment scope
AndroidiOSMobile APIsAuthenticationLocal storageNetwork communicationsDeep linksReverse engineeringRuntime analysis
04

Business logic testing

Understand how your application is designed, then test how its workflows could be abused. Logic flaws require context, curiosity, and manual analysis beyond standard scanners.

Explore assessment scope
Workflow abusePayment & subscription logicPrivilege boundariesState manipulation
02 / ABOUT ME

Curiosity is the starting point.
Evidence is the standard.

I’m a cybersecurity professional focused on penetration testing, application security, and independent research. Practical SOC and security monitoring experience informs how I connect technical weaknesses to real operational risk. My approach combines an Applied Mathematics background with Computer Science studies and hands-on web, mobile, and API security work.

I assess web applications, mobile applications, APIs, authentication systems, and business logic to identify vulnerabilities before they become real-world security incidents.

How I approach an assessment
03 / PENTESTING EXPERIENCE

Context matters. So does confidentiality.

Representative engagement scopes. These examples are not verified client engagements or endorsements.

ENGAGEMENT PROFILE / 01

Education platform

Web application assessment

Web applicationAPIAuthenticationPaid-content access controlsBusiness logic
Testing focus

OWASP Top 10, authorization, authentication, IDOR, business logic, and API security.

ENGAGEMENT PROFILE / 02

University / education platform

Illustrative engagement profile

Web applicationAccess controlAuthentication
Testing focus

Example scope for assessing identity and resource-access boundaries.

ENGAGEMENT PROFILE / 03

SaaS web application

Illustrative engagement profile

APIAuthorizationBusiness logic
Testing focus

Example scope for reviewing tenant boundaries and sensitive workflows.

ENGAGEMENT PROFILE / 04

Real estate mobile application

Illustrative engagement profile

Mobile applicationMobile APILocal storage
Testing focus

Example scope spanning client-side behavior and backend permissions.

04 / SELECTED SECURITY FINDINGS

The finding is only half the story.

Illustrative, anonymized scenarios. Severity labels are examples, not validated ratings for actual engagements.

High · Illustrative

Unauthenticated account lockout

Authentication · Business logic · DoS

An account-security function could allow failed-login events to be generated for arbitrary users without authentication.

Business impact

Potential denial of account access through abuse of the legitimate lockout mechanism.

Remediation overview

Validate request context, throttle abuse, introduce progressive challenges, and monitor lockout patterns.

High · Illustrative

Paid content authorization bypass

Authorization · API security

Inconsistent resource-level authorization could allow access to protected learning content outside the subscription workflow.

Business impact

Potential unauthorized access to premium content and loss of subscription revenue.

Remediation overview

Enforce authorization on every protected backend resource independently of frontend state.

Critical · Illustrative

Unauthenticated database exposure

API security · Data exposure

A generic scenario in which a backend endpoint exposes sensitive database information without appropriate access controls.

Business impact

Potential exposure of sensitive application or user information.

Remediation overview

Require authentication, enforce least-privilege authorization, and minimize returned data.

05 / INDEPENDENT RESEARCH

Look deeper. Question assumptions.

Bug bounty & security research focused on identifying potential high-impact vulnerabilities in real-world applications.

PRIVATE
RESEARCH
META / WHATSAPP SECURITY RESEARCHPrivate Research

WhatsApp for Windows

Potential remote code execution attack chain

Investigated a potential Windows client attack chain involving delivery and execution of script-based content that could, under specific circumstances, result in command execution on the victim system.

Technical details withheld pending validation or coordinated disclosure.

No accepted Meta bounty report, CVE, public disclosure, or official acknowledgement is currently available. This research is not a verified vulnerability.

Some security research presented here remains private and is intentionally described at a high level until validation or coordinated disclosure is complete.

06 / PENTEST CASE STUDIES

From weakness to a way forward.

Illustrative case studies showing how an assessment connects discovery, business impact, and remediation.

CASE STUDY / 01

Authentication abuse & account lockout

Authentication security
Challenge
Evaluate whether authentication protections could themselves be abused.
Discovery
This illustrative scenario examines an anonymously accessible function influencing failed-login counters.
Impact
The legitimate account-protection mechanism could potentially be weaponized to deny users access.
Recommendation
Implement appropriate server-side authorization, per-account and per-IP throttling, abuse detection, progressive challenges, and monitoring.
CASE STUDY / 02

Premium content access control

Authorization & business logic
Challenge
Determine whether premium resources remain protected when interacting directly with backend APIs.
Discovery
This illustrative scenario examines authorization checks enforced inconsistently between application workflows and backend resource access.
Impact
Protected content could potentially be accessed outside the intended subscription workflow.
Recommendation
Enforce authorization on every protected backend resource independently of frontend state.
07 / METHODOLOGY

A deliberate process. No black box.

Testing is conducted only within explicitly authorized scope, with agreed rules of engagement and controlled exploitation.

  1. 01Scope & rules of engagement
  2. 02Reconnaissance
  3. 03Attack surface mapping
  4. 04Authentication testing
  5. 05Authorization testing
  6. 06OWASP Top 10 testing
  7. 07API security testing
  8. 08Business logic testing
  9. 09Controlled exploitation
  10. 10Risk assessment
  11. 11Professional reporting
  12. 12Remediation verification / retest
08 / SKILLS & TOOLS

Human insight. Technical depth.

Tools support the assessment. Manual analysis, application understanding and business-logic testing drive the most valuable findings.

Burp SuiteNmapPostmanffufNucleiMobSFJADXFridaOWASP ZAPWiresharkGitLinuxPythonPowerShell
09 / REPORTING

A report you can
actually act on.

Clear enough for decision-makers. Detailed enough for the engineers fixing the issue.

Sample PDF coming soon.

PENETRATION TEST REPORT
DELIVERABLE OVERVIEW
CONFIDENTIAL
01Executive summary
02Scope
03Risk rating
04Technical findings
05Evidence
06Business impact
07Remediation guidance
08CVSS where appropriate
09Retest results
10 / PROFESSIONAL BACKGROUND

An analytical foundation.

Practical SOC / security monitoring experience
Applied Mathematics background
Computer Science studies
Google Cybersecurity Professional Certificate
LET’S WORK TOGETHER

Need your
application tested?

If you’re preparing a product launch, handling sensitive customer information, or simply want an independent security assessment, get in touch to discuss the scope.