OffSec Certified Professional Plus (OSCP+)
Credential ID: OS-57216833
About
Four years testing web applications, REST and GraphQL APIs, mobile, external networks and Active Directory. Most of what I find is logic: an identifier the server trusts, a state nobody designed for, an authorisation check that verifies the session but not the person holding it.
Alongside the testing, I build autonomous offensive security tooling: agents pairing a deterministic execution engine with LLM decision making, and the scope enforcement and destructive-action controls that any agent holding live credentials actually needs.
I hold OSCP+, CREST CRT and CREST CPSA, and I'm credited with CVE-2026-44977 along with disclosure acknowledgements across healthcare, fintech, AI infrastructure, B2B SaaS, education and civic technology.
Everything I publish here is my own research, tested against systems I own or am authorised to test.
A stored cross-site scripting vulnerability in Countly's feedback upload where the server trusted a client-supplied MIME type, serving attacker-controlled HTML from the application's origin and enabling full session compromise.
Abusing accounts tied to deactivated organisations to reach a hidden signup endpoint, bypassing an invite-only model to create arbitrary accounts and self-select privileged roles.
Open to conversations about offensive security work, research collaboration, and interesting vulnerabilities.