Security engineer focused on recon automation, API security, and GraphQL attack-surface analysis.
I build detection-first tooling for security research and validation workflows. My projects are scoped, transparent, and designed for visibility rather than exploitation.
detection-first · scope-aware · open-source
I design tools that help security teams understand exposure, validate assumptions, and map risk across APIs and GraphQL surfaces.
- Recon automation and workflow orchestration
- API security analysis and auditing
- GraphQL schema inspection and risk classification
- Attack-surface discovery with scope-aware controls
- Open, inspectable output formats for research and validation
REST API security CLI for discovery, auth auditing, and heuristic checks around IDOR, CORS, and rate-limit issues.
Recon orchestration pipeline built around subfinder, dnsx, httpx, naabu, nuclei, and katana with scope-gated execution and diff monitoring.
GraphQL recon and risk analysis toolkit with introspection, classification, schema diffing, SARIF output, and dashboard reporting.
- Hardening
gqlhunterSARIF and reporting surfaces - Improving dashboard tooling and traceability
- Researching broken access control and DOM XSS patterns
- Building safer, more observable security workflows
- Detection-first: analysis and recon before exploitation
- Scope-aware: every request is constrained by allow/deny policy
- Open formats: SQLite, HTML, Markdown, SARIF
- Open source: reproducible, inspectable, auditable
- Security tooling should improve visibility, not increase risk
