Web application testing
Authentication bypasses, IDOR chains, SSRF into internal metadata services, deserialization, and the business-logic flaws that automated scanners never surface. Burp Suite, custom tooling, and a lot of patience.
Available for work
Security Researcher & Ethical Hacker / cyber_anna
I break into applications and networks so the people who own them don't have to find out the hard way — then I help them fix it.
Four disciplines I work in day to day, and the tooling behind each.
Authentication bypasses, IDOR chains, SSRF into internal metadata services, deserialization, and the business-logic flaws that automated scanners never surface. Burp Suite, custom tooling, and a lot of patience.
Stack and heap corruption, ROP chains, format strings. pwntools is a second language.
Ghidra, IDA and x64dbg — unpacking, deobfuscating and reading what a binary won't admit.
Kerberoasting, AS-REP roasting, NTLM relay and BloodHound path-finding — from a single low-privilege shell to Domain Admin.
The attack surface is always larger than the asset list.
Python, Bash and Go. If I do it twice, I script it.
Every engagement starts with a single domain on a scope document.
Certificate transparency, DNS history, a decade of deploys nobody archived.
Each service here is something a person has to remember to patch.
Stood up for a demo, never decommissioned, missing from the asset list.
A perfectly ordinary request. The response is the tell.
It is usually an authorization decision made in the wrong place, on a box nobody owns.
Shared credentials, trusted internal traffic, a flat network. The first host is never the last.
Authorized testing only — happy to talk scope, timelines and what a report looks like.