π Security Researcher | Penetration Tester | Web Security | Active Directory Security | AI & LLM Security
I'm a cybersecurity professional with 3.5+ years of experience in offensive security and security research.
My interests include penetration testing, vulnerability research, exploit development and red teaming.
Currently building security tools, researching vulnerabilities and contributing to open-source security projects.
I also actively write blogs which can be found here.
π Security Engineer
π― Penetration Tester
π€ AI / LLM Security
π₯ Vulnerability Research & Exploit Development
π§ Linux & Active Directory
π οΈ Security Tool Development
π Continuous Learner
- π‘οΈ OSCP Certified
- π Interested in Web, API, Network & Active Directory Security
- π€ Experience with AI Security, Adversarial Testing & LLM Assessments
- π₯ Published conference/journal papers, vulnerability research and exploit PoCs
- π Open-source security contributor
- βοΈ Technical writer covering cybersecurity and vulnerability research
Click here for a full list of my PoC exploits for publicly disclosed CVEs. You can find my Exploit-DB submissions here.
A list of my contributions to open source security tools.
Metasploit
| No. | Exploit | CVE | Status | PR |
|---|---|---|---|---|
| 1 | Arbitrary file read via SSRF in Planyo WordPress plugin | CVE-2026-3576 | Merged | [Link] |
| 2 | User information disclosure via broken access control in 4gaBoards | CVE-2026-53959 | Under Review | [Link] |
| 3 | Arbitrary file read via path traversal in Docmost | CVE-2025-57231 | Under Review | [Link] |
| 4 | Arbitrary file read in WordPress Welcart e-Commerce plugin | CVE-2022-4140 | Under Review | [Link] |
Nuclei
| No. | Exploit | CVE | Status | PR |
| 1 | Arbitrary file read via path traversal in Docmost | CVE-2025-57231 | Merged | [Link] |
My research has been published at top-tier security conferences and journals.
- An adversarial attack approach for eXplainable AI evaluation on deepfake detection models, Computers & Security, 2024 [Link]
- GateKeeper: Operator-centric Trusted App Management Framework on ARM TrustZone, IEEE Conference on Communications & Network Security, 2022 [Link]
- Designing a Text-based CAPTCHA Breaker and Solver by using Deep Learning Techniques, IEEE International Conference on Advances and Developments in Electrical and Electronics Engineering, 2021 [Link]
β If you find my scripts useful, consider giving them a star!


