Security researcher focused on vulnerability research and red team operations. I spend my days finding memory-corruption bugs in software that has a "Trusted" badge on its website, and my nights explaining to vendors why "won't fix" is not a patch.
This blog is where I dump the long version: full exploit chains, tradecraft that survives EDR, and the occasional postmortem of a bug that turned out to be me. No newsletters, no cookie banner, no "we value your privacy."
Static and dynamic analysis, fuzzing, and exploit development against native targets. CVEs, advisories, and the occasional coordinated disclosure that outlives the vendor's patience.
Initial access, evasion, and Active Directory attack paths. Getting to domain admin quietly, then writing the report nobody wanted to read.