Breaking things that need breaking for 20+ years.
Discovered OS command injection in osctrl-admin allowing root/SYSTEM code execution on all enrolling endpoints before osquery installation.
View on NVD →Created one of VulnHub's most popular CTFs with 90+ community writeups over 10 years. Also available on TryHackMe.
View on VulnHub →20 talks at RSA Conference, Security BSides, Forrester Forums, Rapid7 UNITED, and NVTC Capital Cybersecurity Summit.
View talks →Leading offensive privacy testing at TikTok USDS, driving vulnerability research and security assessments across the platform.
LinkedIn →Leading offensive privacy testing and vulnerability research for TikTok's US Data Security initiative. Co-discovered CVE-2026-28279 and CVE-2026-28280 in osctrl.
Researched AI security threats and developed automated security testing methodologies for AI/ML systems.
12 years of penetration testing, red teaming, and social engineering. Spoke at RSA Conference, Forrester Forums, and Security BSides. Featured in Under the Hoodie reports.
Conducted security assessments for state government agencies across Texas.
Security analysis and research at the Center for Infrastructure Assurance and Security at the University of Texas at San Antonio.
OS Command Injection in osctrl-admin. Authenticated admin injects shell commands via hostname parameter in environment configuration. Commands embed into enrollment scripts via Go's text/template and execute as root/SYSTEM on all enrolling endpoints before osquery installation. CWE-78.
Co-discovered with Kwangyun Keum @ TikTok USDS Offensive Privacy Team
Stored XSS in osctrl-admin on-demand query list. Low-priv user injects JavaScript via query parameter. Payload persists and executes in any viewer's browser, including admins. Chainable with CSRF token extraction for privilege escalation and full platform compromise. CWE-79.
Co-discovered with Kwangyun Keum @ TikTok USDS Offensive Privacy Team
20 talks across RSA Conference, Security BSides, Forrester Forums, Rapid7 UNITED, and corporate events spanning 12 years.
Available for speaking, advisory roles, and security consulting.