I'm a Cybersecurity Specialist specializing in Detection Engineering, Threat Hunting, and Penetration Testing. π‘οΈ I'm a passionate learner who loves exploring new vulnerabilities, building robust defense systems, and leveraging AI to automate SOC operations. π
Currently, I'm diving deep into Red Teaming βοΈ and expanding my Adversary Emulation skills π―.
Published CVEs & GitHub Security Advisories
- π΄ [PicPeak (Critical)] Admin Account Takeover via Malicious Backup Restore (GHSA-qxfx-4493-4v8f)
- π‘ [PicPeak (Moderate)] ZIP Slip in Archive Restore (GHSA-jfhw-fj23-fx6x)
- π‘ [PicPeak (Moderate)] Path Traversal via Unsanitized Filename (GHSA-pc72-jf53-w28j)
- π΅ [InvoicePlane] High: CSRF (Recurring Invoice Stop via GET) (GHSA-346c-gqqq-mrm2)
- π΅ [InvoicePlane] Medium: CSRF (Missing Validation on Delete Endpoints) (GHSA-g53q-v2pv-xr83)
- π΅ [InvoicePlane] Medium: IDOR (User Password Change) (GHSA-x38q-xhjj-jr8w)
- π΅ [InvoicePlane] Low: Log Injection via Unsanitized Cron Key (GHSA-9372-vj68-hmc3)
- π΅ [InvoicePlane] Low: Loose Type Comparison in Auth (GHSA-qf9q-2hxm-4wh9)
Open Source Security Contributions
- π΄ [Pennyw0rth/NetExec] Patched critical SSH threading race conditions and Pre2k Directory Traversal vulnerabilities.
- π΅ [SigmaHQ/sigma] Developed and contributed detection rules for eBPF rootkit persistence and abuse.
- π΅ [stamparm/maltrail] Contributed fixes for false positives in network traffic detection heuristics.
π· C.O.R.E.
Enterprise AI SOC AgentΒ· Automates detection, triage & response via LLMs.
π· ARGUS
Next-Gen NDRΒ· Unsupervised Deep Learning to detect zero-day exploits.
π· EREBUS
Dark Web OSINTΒ· AI-Powered Tor crawling + local LLMs (Ollama).
π· Omnisearch
Attack Surface MappingΒ· All-in-one passive recon & web probing utility.
