I work on identity, application security, and red teaming finding the flaws, exploiting them and getting them fixed. I talk about only a subset of them due to [reasons]. Conference talks and slide decks below, alongside advisories and long-form technical breakdowns.
Talks
7Open Relays in 2026: Red Team Initial Access Vectors
Red Team Initial-access TTPs built on open and trusted email relays.
SlidesModern HTML Injection Exploitation
Turning HTML injection into impact against current browser and framework defences.
SlidesBeyond LSASS: Cutting-Edge Techniques for Undetectable Threat Emulation
Entra ID credential-access tradecraft that avoids the detections built around LSASS.
SlidesAdvanced Techniques for Hunting and Securing User Registration Vulnerabilities
Account-registration flaws end to end: enumeration, pre-hijacking and verification bypasses.
SlidesBreaking Business As Usual: Attacking Android Enterprise Solutions
Attacking Android enterprise management stacks, from enrollment through policy enforcement.
SlidesThrow Your (App)Integrity Out the Window: Bypassing Device Integrity Checks on iOS
Defeating the jailbreak and device-integrity checks that iOS apps rely on.
SlidesReverse Engineering Mobile Transit Applications
The research behind the reverse engineering mobile ticketing solutions.
Slides