I break web apps and APIs for a living. Most of my work is access control, business logic, API testing, and proving impact before I write anything up. I care about the fix too: findings should be reproducible and useful to the engineers who receive them.
I'm BSCP-certified. Bug bounty work has earned me €25K+ across 41+ rewarded vulnerabilities. I finished in YesWeHack's Top 10 in Q2 2026.
Outside bug hunting, I spend time on threat modeling, hardening, vulnerability management, IAM/RBAC, and small tools that automate boring work.
| Repository | Notes |
|---|---|
| yeswehack-new-program-watcher | Checks every five minutes, identifies programs by stable ID, and sends new ones to Telegram or Discord. |
| security-monitoring-agent | A Linux agent with HTTP and TLS checks, SBOM and CVE scanning, lightweight DAST, and CI policy gates. |
| techjobs-notifier | Collects and deduplicates recent entry-level tech jobs across Europe. The dataset refreshes daily. |
| kouskous | A ride-hailing architecture with separate client, driver, dispatch, and admin services. Built with NestJS, Flutter, PostGIS, Redis, and Terraform. |
Burp Suite, OWASP ZAP, Python, Bash, JavaScript, GitHub Actions, Terraform, Azure, and Entra ID.



