Offensive Security Consultant
Penetration Testing & Security Consulting Services
I help organizations identify and mitigate real-world security risks across their digital assets.
|
Initializing profile...
Specialized penetration testing services
Comprehensive assessment of web applications and APIs against OWASP Top 10 and business logic flaws. Specialized in authentication bypass, injection attacks, and privilege escalation.
In-depth security testing for Android and iOS applications. Static and dynamic analysis, reverse engineering, and assessment of local storage, inter-process communication, and backend APIs.
Internal network penetration testing with focus on Active Directory environments. Enumeration, privilege escalation, lateral movement, and domain compromise simulations.
Manual and automated security assessment of application source code. Identifying vulnerabilities in PHP, Java, Python, and Node.js applications before deployment.
Internal and external network penetration testing. Server hardening assessment, firewall rule analysis, and vulnerability exploitation on Windows and Linux environments.
Fortify your cloud environments by uncovering misconfigurations and insecure practices. Assessments across AWS, Azure, and GCP for IAM weaknesses, exposed storage, and privilege escalation paths.
Check your AI / LLM applications for exposures and emerging threat vectors. Testing for prompt injection, data leakage, model manipulation, insecure plugin integrations, and OWASP LLM Top 10 risks.
Professional engagements timeline
Certifications and specialized training
Security guides, tools and technical writeups
A comprehensive guide for security-focused source code reviews and regex-based vulnerability detection. Covers manual review techniques, automated tools integration, and pattern matching for identifying security flaws across multiple languages.
View Publication → Published: April 10, 2024Technical preparation guide featuring three Python scripts targeting critical vulnerabilities: deserialization, file upload, and SSTI (Server-Side Template Injection). Designed to aid security professionals in preparing for the OSWE certification exam with practical exploit development techniques.
View Publication → Published: November 19, 2025Advanced command-line tool for comprehensive security analysis of Android APK files with detailed JSON reporting. Automates static analysis, permission analysis, and vulnerability detection for mobile applications.
View Tool →Ready to secure your digital assets? Let's talk.