I FIND THE flaws BEFORE THEY FIND YOU.
Comprehensive penetration testing across web, Android, IoT, and access-control hardware. Custom payloads, EDR/DLP bypass, and reproducible PoCs with strategic remediation — the kind of report your security team can act on.
Red Team & APT Sim
Multi-stage Red Team engagements, realistic APT simulations, custom payload development, EDR & AV evasion.
Web App Pentest
OWASP-aligned testing — SQLi, SSRF, SSTI, XSS, broken auth/authz. 200+ engagements completed.
Android Pentest
Static & dynamic Android assessments with MobSF, APKTool, Frida, Objection, Jadx. eWPTX-grade rigor.
IoT & Hardware
Firmware and hardware-level review of IoT devices, access-control hardware, biometric data, and telco assets.
iOS jailbreak detection bypass — a Frida + Objection field guide
Banking apps, e-wallets, and DRM clients all run a JB check before they trust their own code. The seven detection patterns and the runtime hooks that disarm each one.
Defeating Android SSL pinning in 2026 — a Frida-first methodology
The universal pinner script doesn't cut it anymore. A working playbook covering OkHttp, X509TrustManager, Network Security Config, custom validators, and native-layer pinning.
Server-Side Template Injection — from leak to RCE across five engines
A working playbook for SSTI in 2026 — engine fingerprinting, sandbox escapes, and the chains that get from a shell on Jinja2, Twig, Freemarker, Velocity, and ERB.