About me

I am an experienced penetration tester with a strong background in web-application security. I have disclosed vulnerabilities in organizations such as Microsoft, EE, TripAdvisor, The British Broadcasting Corporation, and EA.




Blue is an AIO web-based reconnaissance panel covering sub-domain enumeration, CMS and software detection via signatures and fingerprints, Google dorking, email harvesting, subdomain takeover scans, zone transfer checks, and more. Blue utilizes API’s from Shodan, Hunter.io, VirusTotal, and Spyse. Blue has a secure authentication system, automated payment and credit systems, and an automated report builder. Blue is written in Python 3 on top of the Flask framework.


ComScan spiders a given domain and scans all found files for comments in hopes of finding hard-coded passwords and API keys or other sensitive information. ComScan is written in Python 3, and makes use of many different libraries.


GitMail is a tool designed to be used during the OSINT stage of reconnaissance or for profiling in social engineering engagements. GitMail obtains email addresses of GitHub users, even when they have privacy options enabled, by scraping Git commits. GitMail is written in Python 3.


AT&T Hall of Fame
Microsoft Hall of Fame (Apr. 2017)
