// security researcher & bug hunter
Find. Report.
Secure.
Bug hunter finding and reporting vulnerabilities in web applications and APIs.
// experience
Bug Bounty
I hunt vulnerabilities in web applications and APIs, disclosing them responsibly through public and private bug bounty programs. My focus is manual testing — access control flaws, business logic errors, and auth issues that scanners miss — backed by automated tools when it helps widen coverage.
~/hackerone/g3ksec
Hunting In
// skills
Technical Skills
Web Assessment
Reconnaissance
Scripting & Review
// research & disclosure
Writeups
Bug reports and research I've published.
// builds
Projects
Tools I've built.
~/hxhunt
HxHashFavicon
Favicon fingerprinting tool to extract Shodan/Fofa compatible MurmurHash3 signatures. Useful for asset discovery and mapping hidden attack surfaces.
HxBugLetter
Self-curating archive of verified bug bounty writeups and research. A GitHub Actions bot fetches trusted sources daily, classifies each entry, and auto-commits it — content-as-code, no database.
HxBugLabs
Self-hosted, Docker-based labs for practicing bug bounty vulnerabilities and recon techniques. IDOR, XSS, SSRF, auth, and OSINT — each a real app with multiple objectives, nothing telegraphed in the UI.
