Red Teamer · Security Researcher · Full-Stack Engineer
I break systems to understand them, then build the tooling that makes the next break faster.
Offensive-security practitioner working across the full attack lifecycle — recon, exploitation, post-exploitation, and C2 — plus the engineering side that supports it. My public work spans red-team tradecraft (C2 evasion, EDR bypass), web-app and bug-bounty methodology, and production-grade full-stack and ML systems. I build tools I actually use and document the methodology so it's repeatable. Currently deepening red-team automation and adversary emulation.
Daily-refreshed still (renders after the workflow's first run)
The preview above is a recording of the live WebGL / Three.js scene (source), which pulls contribution data in real time. GitHub READMEs can't run JavaScript, so true interactive 3D lives on GitHub Pages and is one click away. The collapsible still is regenerated daily by a GitHub Action (
github-profile-3d-contrib). See the setup checklist below.
Offensive Security
- C2-Evasion-Toolkit — Red-team C2 stealth: polymorphic payload generation (Go), in-memory C# execution with API hashing for EDR bypass, and domain fronting for network-level cover.
- bugbounty-arsenal — Web-app pentesting & bug-bounty kit: methodology, checklists, custom recon / broken-access-control / API tooling, and hands-on vulnerable labs.
- cybersecurity-resources — Curated references, scripts, tools, labs, and training material — the reference library behind the rest of the work.
Engineering
- vivasec — VivaSec: a unified privacy super-app (TypeScript).
- trackml-mlops-pipeline — End-to-end MLOps: MLflow tracking + model registry, Optuna sweeps, an automated promotion gate that refuses regressions, and FastAPI serving that resolves the live production model from the registry.
Offensive Security & Tooling
Languages
Frameworks & Data
Cloud & Infra
