Red Team Engagement
Full-scope adversary emulation with PoC chains and prioritized remediation actions.
$ ls ./projects/
A selection of offensive security work — engagements I deliver to clients and open-source exploits I've published for disclosed CVEs.
Full-scope adversary emulation with PoC chains and prioritized remediation actions.
Automated & manual testing across web, API, network, cloud — exploit-evidenced findings with remediation steps.
Manual review for backend/frontend with annotated vuln snippets, severity, patches and a secure-coding checklist.
Comprehensive review of network architectures, configs and security controls for hardened deployment.
Engineered containerized environments for CTFs with unique per-team flags to prevent sharing.
CTFd plugin that automates user verification, syncs nicknames with CTFd usernames and assigns roles.
CVE-2023-38646
Metabase Pre-auth RCE
Python · ★ 15
CVE-2023-49070
Apache OFBiz Pre-auth RCE
Python · ★ 1
CVE-2022-22965
Spring4Shell RCE
Python · ★ 3
CVE-2021-41349
Microsoft Exchange Server Spoofing
HTML · ★ 5