Software engineering / offensive security
I map the edges where software breaks.
I’m fir3cr4ckers, a security researcher and software engineer documenting real attack paths, technical experiments, and the systems I build along the way.

Latest signals
Recent field notes
- OpenWriteups
Intigriti August 2026 Challenge Writeup: Bad Reception
Chaining stored HTML injection with CVE-2024-9966 to bypass CSP and reach the bot-only channel 11.
- OpenWriteups
Patriot CTF 2k24 Writeup
Patriot CTF 2k24 Web/Rev Challenges Writeup
- OpenWriteups
HTB Business CTF 2023
HTB Business CTF 2023 Web Writeups
- OpenWriteups
TAMU CTF 2K23 Web challenges
TAMU CTF 2K23 Web challenges Writeup
- OpenWriteups
NCSC 4.0 CTF Author's writeup - Web exploitation
NCSC 4.0 CTF Author's writeup - Web exploitation
Built systems
Selected projects
- OpenProject
Project Ein
Ein revolutionizes penetration testing with its template-based declarative attack system, Go-powered engine, AI-assisted template generation, and a sleek Svelte frontend.
- OpenProject
Labyrinth: A Dynamic Penetration Testing Lab
Developed during an internship at EY, Labyrinth is a dynamic penetration testing lab built with Docker that helps cybersecurity professionals hone their skills in a realistic and challenging environment.
- OpenProject
C2 Chopper Framework
A flexible and extensible C2 framework built with Golang and React for managing red team operations during penetration testing missions.
Open channel
Let’s compare notes.
Have a research idea, an interesting system, or just want to say hello? My inbox and social channels are open.