Independent web application security research — penetration testing, vulnerability analysis, and exploitation write-ups.
Manual assessment of authentication, access control, and injection flaws across modern web stacks.
Identifying and chaining logic flaws — IDOR, XXE, verb tampering — into practical exploits.
Reviewing REST and GraphQL endpoints for broken object-level authorization and data exposure.
Commercial-grade findings with clear reproduction steps and remediation guidance.