Ethical Hacking · Responsible Disclosure

Find flaws.
Build trust.

I'm an independent security researcher hunting on HackerOne, focused on web application and API security. I look for real, exploitable vulnerabilities and report them responsibly — no noise, no guesswork, just verified findings.

Focus: Web & API Security Platform: HackerOne Approach: Manual verification, always
SecureHunter — security researcher illustration
What I do

Areas of focus

Security research grounded in manual verification — not scanner output dressed up as a finding.

Bug Bounty Research

Hunting for vulnerabilities through HackerOne-hosted programs, within each program's defined scope and rules.

Web Application Testing

Authentication, session handling, access control, injection points, and business-logic edge cases.

API Security

Auth bypass, IDOR, schema abuse, and misconfiguration testing across REST and GraphQL APIs.

Responsible Disclosure

Clear, reproducible reports with verified impact — written to help teams fix issues fast, not to pad a count.

Our Approach

A methodical process

Every finding goes through the same discipline before it's ever written up.

01

Recon

Map the target and confirm what's in scope.

02

Testing

Manual + tool-assisted probing of attack surface.

03

Verification

Confirm real, reproducible impact — reject false positives.

04

Reporting

Clear write-up with PoC, steps, and severity.

05

Follow-up

Support retesting once a fix ships.

$ whoami
securityresearcher — web/api security
$ cat approach.md
1. Recon & scope review
2. Manual + tool-assisted testing
3. Verify impact before reporting
4. Clear, reproducible write-up
$
About

Security researcher focused on precision, not volume

My process is deliberate: understand the target, test methodically, and verify real, reproducible impact before ever calling something a vulnerability. Every report I submit is written the way I'd want to receive one — clear, evidenced, and easy for a triager to act on fast.

I'd rather submit fewer, high-quality reports than chase volume with scanner output. That discipline is the standard I hold every finding to.

Burp Suite nmap sqlmap nuclei ffuf Python Linux

Have a report or want to get in touch?

For vulnerability disclosures or general inquiries, reach out below.