Ethical Hacking · Responsible Disclosure

Find flaws.
Build trust.

I'm an independent security researcher hunting on HackerOne, focused on web application and API security. I look for real, exploitable vulnerabilities and report them responsibly — no noise, no guesswork, just verified findings.

Focus: Web & API Security Platform: HackerOne Approach: Manual verification, always
$ whoami
securityresearcher — web/api security
$ cat approach.md
1. Recon & scope review
2. Manual + tool-assisted testing
3. Verify impact before reporting
4. Clear, reproducible write-up
$
What I do

Areas of focus

Security research grounded in manual verification — not scanner output dressed up as a finding.

Bug Bounty Research

Hunting for vulnerabilities through HackerOne-hosted programs, within each program's defined scope and rules.

Web Application Testing

Authentication, session handling, access control, injection points, and business-logic edge cases.

API Security

Auth bypass, IDOR, schema abuse, and misconfiguration testing across REST and GraphQL APIs.

Responsible Disclosure

Clear, reproducible reports with verified impact — written to help teams fix issues fast, not to pad a count.

Our Approach

A methodical process

Every finding goes through the same discipline before it's ever written up.

01

Recon

Map the target and confirm what's in scope.

02

Testing

Manual + tool-assisted probing of attack surface.

03

Verification

Confirm real, reproducible impact — reject false positives.

04

Reporting

Clear write-up with PoC, steps, and severity.

05

Follow-up

Support retesting once a fix ships.

SH
About

Security researcher, building a track record one verified report at a time

I'm relatively new to bug bounty hunting and building my track record openly on HackerOne. My approach is deliberately unglamorous: understand the target, test carefully, verify impact before ever calling something a vulnerability, and write reports that are easy for a triager to act on.

I'd rather submit fewer, high-quality reports than chase volume with scanner output — that's the reputation I'm building.

Burp Suite nmap sqlmap nuclei ffuf Python Linux

Have a report or want to get in touch?

For vulnerability disclosures or general inquiries, reach out below.