Web application security and penetration testing, built through hands-on labs and self-written tooling:
- SQL injection — including blind SQLi
- Access control / IDOR
- SSRF
- XSS
- Path traversal
- Offensive Python — scanners, brute-forcers, exploit helpers
- HTTP internals, proxies, and raw sockets
- PortSwigger Academy — web security lab writeups with payloads and root-cause analysis
- HTB writeups (private) — independent enumeration and exploitation reasoning
- TryHackMe Writeups — notes across Pre-Security, Cyber Security 101, and Jr Penetration Tester
- labs — exploitation writeups against Metasploitable 2, DVWA, and WebGoat
- pentools — Python toolkit: port scanner, hash cracker, and a blind SQL injection extractor
- http-proxy-lab — HTTP proxy and request parser built from raw sockets
- dir-brute — multithreaded directory brute-forcer and crawler
- DOM-based XSS and JavaScript fundamentals for web security
- Authentication, API security, and JWT
- Business-logic vulnerabilities
- Hack The Box and independent target enumeration
- Penetration-testing methodology
Cybersecurity internships in application security and penetration testing.
