name: _BI6D4DDY_ role: Penetration Tester | Security Researcher | Offensive Security focus: Web/Cloud Security, Active Directory Attack Chains, Mobile Security (iOS/Android) side_quest: Python data engineering & report automation currently: Building out a full mobile pentesting lab (Frida, Objection, MobSF)
π Web / Cloud Security
- GraphQL & REST API abuse (IDOR, auth bypass)
- JWT attacks (algorithm confusion, cracking)
- Azure cloud misconfig (SAS tokens, blob storage IDOR)
- Recon: JS bundle analysis, endpoint enumeration
- Exposed
.gitdirectory & secret hunting
π’ Active Directory / Internal
- Kerberoasting, AS-REP Roasting
- Pass-the-Hash / Pass-the-Ticket / Golden-Silver Tickets
- BloodHound-driven privilege escalation
- Windows priv-esc: Juicy Potato, service abuse, persistence
π± Mobile Security
- Android & iOS static + dynamic analysis
- SSL pinning bypass with Frida / Objection
- MobSF, drozer, jadx
- OWASP MASVS-aligned assessments
π Automation / Data Engineering
- Python data pipelines (MongoDB β Excel)
- Secret-extraction & recon tooling
- Report automation with openpyxl
[+] Enumerating attack surface...
[+] Fuzzing GraphQL / REST endpoints for IDOR...
[+] Cracking JWTs (alg confusion, weak secrets)...
[+] Kerberoasting hq.vanguard.bank AD lab...
[+] Bypassing SSL pinning on Pixel 7 / iPhone X...
[+] Chaining vulnerabilities into full compromise...
[+] Documenting findings...
[+] Repeat.
π― Currently working on
- Active Directory attack-chain lab (
hq.vanguard.bank) β Kerberoasting, BloodHound, priv-esc - Full mobile pentesting lab across iPhone X + Pixel 7
- Bug bounty research on HackerOne & Bugcrowd (GraphQL IDOR, Azure cloud misconfig, JWT attacks)
- Python-based recon & secret-extraction tooling
Swap
d4w0dfor your real GitHub handle to activate these live cards.