About
Who I am
How I work
The findings that interest me are the ones a scanner cannot reach: authorisation derived from a value the caller controls, a workflow that can be completed out of order, a mobile client that trusts its own device. Those take reading the application, not running a tool against it.
On Android that means static analysis with jadx and Ghidra, modifying SMALI where the logic needs changing, hooking at runtime with Frida, and getting between the app and its server even when it pins certificates.
Every engagement ends in a written report with a working proof-of-concept and a remediation step, because a finding nobody can reproduce is not a finding.
Education
Certifications
Listed with their real state. Self-study in progress is shown as in progress, never as a credential held.
Earned
- Android App SecurityCertificate heldEarned
In progress
- eWPTXINE / eLearnSecurity — self-studyIn progress
- OSCPOffSec — self-studyIn progress
- CCNACiscoIn progress
Next
Deeper coverage of the Android attack surface, more published findings from bug bounty work, and a first CVE.