Security researcher — 20 yrs. carrier voice & network infrastructure

I spent two decades tracing signals. Now I trace attack paths.

Senior network engineer turned pentester. eJPT certified, in-house pentesting experience since 2022, and a growing focus on web application security — documented here, one finding at a time.

Voice / network — 2007–2022 Web app security — 2022–present

Focus areas

PORT 01 — WEB

Web Application Security

Auth flaws, access control, SSRF, injection, and business logic issues — tested the way I'd explain them to the business that owns the app.

PORT 02 — NET

Network Penetration Testing

Internal and external network assessments, built on years of running the infrastructure I now test.

PORT 03 — VOICE

Telecom & VoIP Infrastructure

A niche most testers don't have: hands-on experience with Asterisk variants, Avaya, Kamailio, and other carrier-class switching platforms, from the inside.


Recent writeups

No writeups published yet — first one coming soon.