Research
Offensive security research on the modern web and industrial control systems: papers, CVEs and advisories.
What I do
Offensive security research on the modern web and industrial control systems: papers, CVEs and advisories.
Where I started, and still something I do: pentesting, bug bounties and collegiate competitions.
I build the tools I wish existed, like JS Recon, and publish them for everyone to use and break.
Selected research
ASE 2026 · Research Papers
Automated semantic recovery of post-compilation abstraction leaks in web apps.
ASE 2026
An LLM agent for logic-defined exposures in recovered JavaScript.
CISA ICS Advisory
Vulnerabilities in an open-source PLC runtime, coordinated through CISA.
Critical · CVSS 9.3
I wrote a command injection into my own tool's CI, found it ten months later, and patched it.
Open-source projects

A powerful tool for JavaScript reconnaissance - discover, download, and analyze JS to uncover endpoints, secrets, and reconstruct HTTP requests to OpenAPI.

A deterministic hashing scheme for general-tree ASTs in SAST scanners, enabling reliable subtree fingerprinting and constant-time node lookup via Merkle-style signatures.

Virtual Host Fuzzer written in Python

A list of commonly found subdomains
Writing
After 2 months of development, I gave my first presentation at RITSEC, which is the cybersecurity club at Rochester Institute of Technology.
Moltbook can be a vector for prompt injection attacks. In this presentation, I tried to prove my hypothesis with findings I had from past week's data collection.
GraphQL is getting widely adopted for APIs, but with features, it also brings home vulnerabilities.
I got my first cybersecurity internship at a high-school, without a degree. Here's how!
I did wardrive,,,, without a proper wardrive gear, but with a raspberry pi, and my centuries old mobile phone.