Initialising 000
b1tbreaker@root:~#/
Currently — Senior Penetration Tester Offensive security · Vulnerability research

VmFzaWxpcyBGbGV

Ethical hacker. I break things before someone else does.

Cybersecurity professional specializing in penetration testing and vulnerability research. I enjoy bypassing defenses, discovering new attack paths and helping organizations improve their security.

b1tbreaker@root:~#

b1tbreaker@root:~#

Scroll to explore
01 Capabilities

What I actually do

Black, grey and white-box testing of modern web stacks including single page applications, REST or GraphQL APIs and the SSO integrations that hold them connected. Focus areas include broken access control, authentication and session flaws, injection, insecure deserialisation andbusiness-logic abuse. Individual findings chained into one realistic path to impact. Where source code is available, code reviewis used to guide and deepen the testing.

OWASP Top 10Burp Suite Source Code ReviewGraphQL OAuth / SSOBusiness Logic

Static and dynamic assessment of iOS applications using jailbroken devices to examine application behaviour beyond the intended security boundary. Analysis covers application binaries, Objective-C and Swift internals, Frida based runtime instrumentation, authentication and cryptographic controls, keychain and local storage, URL schemes, IPC and protections such as SSL pinning and jailbreak detection. Third-party SDKs, libraries and frameworks are also examined for insecure integrations, exposed functionality and weaknesses introduced through their use.

FridaObjection TheosKeychain Pinning BypassOWASP MASVS

Reverse engineering of APKs down to their native libraries, runtime manipulation with Frida or Objection and a full review of whatever the application leaves behind on the device. Insecure data storage, exported components, intent abuse, WebView or deep-link issues, home-made cryptography and the root detection worth bypassing to see what sits underneath.

APK ReversingSmali FridaExported Components WebViewIntent Filters

Full domain attack-path analysis, from initial network access through high-impact domain compromise. Kerberos abuse including Kerberoasting, AS-REP roasting, constrained and unconstrained delegation is assessed alongside ACL and trust misconfigurations, Active Directory Certificate Services abuse, credential harvesting, NTLM relay and lateral movement. Graph-based analysis maps the relationships between users, groups, systems, privileges and authentication paths to uncover practical attack chains rather than isolated theoretical weaknesses.

KerberosBloodHound NTLM RelayAD CS Lateral MovementImpacket Suite

Authorised phishing campaigns designed to measure real human risk rather than tick a compliance box. Pretext development, campaign infrastructure and domain setup, credential capture, payload delivery all supported by OSINT driven target profiling. Every engagement is scoped and agreed in advance, then reported alongside the detection gaps that let it through.

PhishingOSINT PretextingPayload Delivery Awareness Metrics

Mapping the external attack surface to understand what an organisation actually exposes to the internet. Perimeter discovery and subdomain enumeration, service and technology fingerprinting, forgotten management interfaces, legacy infrastructure, exposed cloud resources and misconfigured services. Exploitation of internet-facing weaknesses to establish whether an exposed service represents a genuine path to compromise rather than a theoretical finding.

ReconAttack Surface NmapSubdomain Enumeration Perimeter Breach

Independent vulnerability research across software and technologies in real-world use. Source code review, fuzzing, reverse engineering, and targeted analysis are used to uncover vulnerabilities, design flaws and unexpected attack paths. Discovered issues are validated, reproduced and responsibly disclosed to affected vendors, with proof-of-concepts developed where appropriate.

3 CVEs assignedResponsible Disclosure FuzzingPatch Diffing Code Review
02 Selected research

Disclosed vulnerabilities

03 Writing

From the blog