> whoami
Finding vulnerabilities before attackers do.
Breaking things
(ethically) so they can't be broken maliciously.
about.md
Hey, I'm roxoi — a bug hunter and cybersecurity researcher. I spend my time looking at systems the way an attacker would, then reporting what I find before someone with worse intentions gets there first.
My work spans web application security, vulnerability research, and bug bounty hunting — digging through auth flows, APIs, and business logic to find the edge cases that break things.
Security isn't a checklist for me, it's a mindset: assume everything is attackable until proven otherwise.
Bug bounty hunting across web and API targets — chasing auth bypasses, injection flaws, and logic errors.
Structured, methodology-driven testing of applications and infrastructure to surface real-world risk.
Deep-dive analysis into how software fails — root-causing bugs and understanding their exploitability.
tech.json
findings/
Reported & Triaged Vulnerability
Placeholder write-up: found a broken access control flaw in an API endpoint that allowed privilege escalation between user roles. Replace with your own disclosed report.
Read Write-up →Bug Bounty Report
Placeholder write-up: a blind SQL injection uncovered in a search feature, escalated to full database read access. Replace with a link to your disclosed report or CVE.
Read Write-up →Custom Security Tooling
Placeholder project: a custom recon pipeline chaining subdomain enumeration, port scanning, and vulnerability scanning for faster bug bounty triage.
View on GitHub →Capture The Flag Challenges
Placeholder: a collection of write-ups from CTF competitions covering web exploitation, reverse engineering, and crypto challenges.
Read Write-ups →Simulated Assessment
Placeholder: a simulated internal pentest engagement covering lateral movement, privilege escalation, and Active Directory misconfigurations.
Read Report →> more_findings.sh
Check my GitHub and bug bounty platform profile for additional write-ups and disclosed reports.
Full Profilecontact.sh
Found a bug in your product and need it reported responsibly? Need a security assessment? I'm one message away.