I work on identity, application security, and red teaming finding the flaws, exploiting them and getting them fixed. I talk about a subset of them due to [reasons]. Conference talks and slide decks below, alongside advisories and long-form technical breakdowns.
Talks
52025
Beyond LSASS: Cutting-Edge Techniques for Undetectable Threat Emulation
Entra ID credential-access tradecraft that avoids the detections built around LSASS.
Slides2024
Advanced Techniques for Hunting and Securing User Registration Vulnerabilities
Account-registration flaws end to end: enumeration, pre-hijacking and verification bypasses.
Slides2023
Breaking Business As Usual: Attacking Android Enterprise Solutions
Attacking Android enterprise management stacks, from enrollment through policy enforcement.
Slides2023
Throw Your (App)Integrity Out the Window: Bypassing Device Integrity Checks on iOS
Defeating the jailbreak and device-integrity checks that iOS apps rely on.
Slides2019
Reverse Engineering Mobile Transit Applications
The research behind the reverse engineering mobile ticketing solutions.
SlidesWriting & Advisories
42021