Web & API Security
Testing web applications and APIs for auth flaws, IDOR, injection, upload issues, SSRF, and broken access control.
Cybersecurity portfolio + blog
My experience spans offensive security, CTF challenges, and threat intelligence research, with notes that turn useful lessons into readable writeups.
Elite Hacker / Guardian / WillHack4Coffee / Komnot
Skill stack
Testing web applications and APIs for auth flaws, IDOR, injection, upload issues, SSRF, and broken access control.
Mapping attack surface, validating weaknesses, prioritizing impact, and documenting findings clearly.
Solving pwn and web challenges, building repeatable exploit paths, and turning solves into readable writeups.
Researching signals, public-source pivots, exposed infrastructure, adversary behavior, and clean investigation notes.
Credentials
WillHack4Coffee placed 1st in Cyber Arena 2026, an online CTF competition with 157 teams.
Top 1- CTFWillHack4Coffee placed 1st with 13,156 CTF points in Sieberrsec CTF 7.0, an online CTF competition with several teams.
Top 5- CTFI placed 5th in KOH KER OSINT CTF 2025, an in-person OSINT CTF competition.
Top 1- StartupKomnot placed 1st in the Finclusion Innovate Competition by presenting cybersecurity solutions that help people detect and avoid scams.
Top 2- StartupKomnot placed 2nd in Innovative Tech Challenge Season 3 by presenting cybersecurity solutions "Komnot App" that help people detect and avoid scams.
Final Round- StartupKomnot qualified for the final round in Hanoi, Vietnam by presenting cybersecurity solutions, "Komnot App" that help people detect and avoid scams.
Entry-level cybersecurity certification covering security principles, access controls, network security, and incident response fundamentals.
Builds a baseline across core security concepts: identity and access, network defense, risk, operations, and incident response.
View certificateProjects
Demonstrate ransomware behavior with AES-based file encryption and RSA key protection, covering payload workflow, attack assumptions, and defensive measures.
Open ProjectBlog
Jun 27, 2026 / Pwn
Cyber Arena 2026 - Pwn - Format string exploitation against a PIE binary: leak main, recover the PIE base, then read the hidden flag buffer with a controlled %s dereference.
Read writeupJun 27, 2026 / Pwn
Cyber Arena 2026 - Pwn - Heap use-after-free in an encrypted protocol, recover a hidden keeper secret, and unseal the flag.
Read writeupContact
Verified hack platform profiles, GitHub, and LinkedIn are the best contact paths for now.