AI Trust Boundaries
Tested HubSpot's Breeze AI across 17 attack vectors and found its email and CRM-note pipelines treat trust differently — opening an indirect prompt-injection path. Reported through HackerOne and written up in full.
AI securityPrompt injectionHackerOne
Read case study →WAVE
Web Automation Vulnerability Explorer — a Kali CLI scanner for bug-bounty recon: XSS, SQLi, NoSQLi, command injection, SSRF and access-control checks, plus subdomain/API discovery and automated HTML & JSON reports.
PythonBashBug bounty
See it in action →WNSA
Wireless Network Security Analyzer — a Linux-native 802.11 workbench: AP and client discovery, monitor-mode capture, WPA2/WPA3 handshake assessment and packet analysis in one PySide6 interface, for authorized labs.
PySide6802.11airodump-ng
See it in action →NeuralOps
An AI-powered Security Operations Center. It ingests security events, triages them with an AI analyst, maps activity to MITRE ATT&CK, and streams real-time incident alerts to a live command dashboard.
PythonGeminiMITRE ATT&CK
See it in action →Echo Defend
Security-operations automation that handles authorized command retrieval, local CLI execution, result capture and webhook delivery — a lightweight ops pipeline for controlled, authorized environments.
PythonAutomationWebhooks
See it in action →Capture the Flag
Competing across campus, national and online events — a few podiums, plenty still in progress. 1st at Flagwars, top 10 at SIMLE, and 88th of 180,000+ at the TryHackMe Industrial CTF. Still grinding.
CTF
See my CTF journey →