For over 25 years I operated on both sides of cybersecurity. I built botnets, ran massive infrastructure, and bypassed world-class defenses. Today I use that unique experience to find vulnerabilities others miss โ and help organizations defend themselves for real.
Services
Web Application Pentest
OWASP Top 10, business logic flaws, authentication, session management, XSS, SQLi, SSRF, and beyond.
Infrastructure & Network
External and internal pentesting, Active Directory attacks, network segmentation review, server and service vulnerability discovery.
API Security
REST, GraphQL, gRPC โ authorization testing, rate limiting, injection attacks, data leakage through API endpoints.
Cloud Security
AWS, GCP, Azure โ configuration audits, IAM policies, S3/GCS buckets, serverless, Kubernetes security.
Smart Contract Auditing
Solidity, DeFi protocols โ reentrancy, flash loans, oracle manipulation, access control, economic exploits.
Red Team & Social Engineering
Real-world attack simulation, phishing campaigns, physical pentesting, employee resilience assessment.
Why Me
I didn't learn to hack from textbooks โ I wrote those textbooks. Building Storm, Waledac, and Kelihos gave me deep understanding of how real attacks work, not theoretical models. My clients get an audit from someone who thinks like an attacker โ because I was one.
How It Works
Reconnaissance & Planning
Define scope, gather intelligence, agree on rules of engagement and constraints.
Testing
Active penetration testing with manual and automated techniques. Vulnerability discovery, exploitation, post-exploitation.
Report
Detailed report with vulnerability descriptions, severity ratings, proof-of-concept, and remediation guidance.
Retest
Verify fixes, confirm remediation, deliver final report.
Publications
"CyberFortress" (2024)
Comprehensive guide to computer security โ from cryptography to incident response.
"Python from Scratch" (2024)
Practical introduction to Python โ from basics to OOP and web scraping.
"New Finance" (2024)
Blockchain, DeFi, Web3 โ technology, investing, and security.
Contact
Ready to discuss your project. Write me โ I respond within 24 hours.