Application security engineer, researcher, and trainer. Most of my work sits at the intersection of breaking things, figuring out why they broke, and teaching other people how to do both.
- Focused on offensive security: appsec, penetration testing, and exploit development.
- I write and teach, from bug bounty fundamentals to full assessment reporting.
- Find every link in one place at links.martian1337.com, or reach me on LinkedIn.
- I run a cybersecurity Discord community. Come say hi.
- Application Security for web and mobile, from source review to exploitation.
- Penetration Testing across networks, web apps, and mobile targets.
- Cloud Security for hardening infrastructure and services.
- IoT Security and the risks specific to connected devices.
- Threat Analysis to identify, prioritize, and mitigate.
- Security Training delivered to teams and individuals.
Languages I read, script in, and test against:
Tools I reach for on engagements:
DevSecOps and CI/CD security:
Application security and vulnerability management:
SIEM, cloud, and monitoring:
Workflow and platforms:
Operating systems:
|
Web recon tool for gathering open source intelligence during engagements. |
A living reference of notes, techniques, and checklists for security work. |
|
A curated start page of tools and resources for pentesters and researchers. |
Walkthroughs, tooling, and training content on offensive security. |
Latest posts:
- Beginner’s Guide to Packaging and Distributing Dockerized Apps Across Major Linux Distributions
- Duplicati: Bypassing Login Authentication With Server-passphrase
- How I was able to Zero Click Account takeover with 3 different ways on the same Reset Password…
- Bypassing Reset Password ATO (Account takeover) through JavaScript Breakpoints
- Analyzing Game Cheats With StrCat
Full archive
- Deploy vulnerable web applications for Application Security (AppSec) training in under 25 minutes (System Weakness Publication)
- eWPT to eWPTX Certified in 45 days (without INE labs): Exam Review and Tips (System Weakness Publication)
- Exploiting CVE-2022-42889 (Text4Shell/ACT4Shell) (System Weakness Publication)
- The Application Penetration Testing Process: A checklist for every engagement
- Bug Bounty for Beginners (Part 1): Utilizing OWASP to get into BBPs
- Bug Bounty for Beginners (Part 2): Recon for Modern Bug Bounty Hunting
- Bug Bounty for Beginners (Part 3): Understanding The Reporting Process
- Cybersecurity Risks of 5G connectivity on IoT devices
- Outlining the Vulnerability Assessment Report
- Outlining the Penetration Test Report
- Unveiling Trickest: My Secret Weapon for Automating the Bug Bounty Hunt (Published in Intigriti's Bug Bytes)
- Mobile App Pentesting: AndroGOAT Assessment Walkthrough (Published in InfoSec Writeups Blog)
- Google Dorking and Shodan Exploration for Beginners: Unveiling Exposed Webcams
Stay curious, test everything, trust nothing.
Explore more at Martian Defense.




