Whoami

Security researcher and software engineer. I find bugs, contribute to open source, and break things professionally.

20266
Apr 2026

Discovered another high-severity vulnerability for Netflix ($5,000 bounty).

Mar 2026

Built Scarecrow, an adversarial pattern optimizer for evading automated license plate recognition. Designed as a privacy tool against warrantless mass surveillance.

Feb 2026

Reached 99th percentile on HackerOne with a 7.00 signal rating.

Jan 2026

Disclosed a DoS vulnerability in Node.js TLS error handling (CVE-2026-21637, ~$1,000 bounty).

Jan 2026

Discovered a high-severity vulnerability in Netflix production systems ($5,100 bounty).

Dec 2025

Joined HackerOne to hunt for bug bounties in order to help pay off student loans and university expenses.

May-Dec 2025

IT Security Engineer at Think Big Technology, where I managed security operations for two client organizations and mentored an intern in SOC operations.

Jun 2024-Jan 2025

Taught Python, Java, and C++ to K-12 students at The Coding Place. Turns out explaining pointers to 12-year-olds is harder than reversing malware.

Dec 2023

WKL-Sec adapted my HVNC project into a Cobalt Strike module, bringing it into commercial offensive security tooling.

Aug 2023

Built VisualSploit (C#) to demonstrate MSBuild exploitation. Malicious .csproj files that execute code through trusted build processes. Based on that 2021 NK supply chain attack against security researchers.

Mar 2023

Reverse engineered live malware from Venom RAT, Pandora HVNC (both C# .NET). Shared IOCs with Antivirus vendors via VirusTotal.

Sep 2022

Fixed, modernized, and reconstructed HVNC in Tinynuke as standalone client/server (C++). Posted to GitHub as my largest software undertaking to date.

Apr 2021

Signed up to crackmes to learn reverse engineering. Learned Ghidra for native code, DnSpy and ILSpy for .NET apps.

Feb 2021

Built my first RAT (C#) - the delivery was process injection + RunPE. Learned NTDLL unhooking to bypass userland hooks.

2019-2020

Self-taught Python, C#, Java, C++, and web dev during COVID lockdown. Hundreds of hours of youtube, dozens of pet projects, and thousands of cups of coffee later, I was half-decent.