Security
Offensive security work. Bug bounty, web application testing, and the tooling I build to do it.
2 posts in this category
-
Teaching AI to Hunt What Humans Miss: Building a Bug Bounty Brain That Thinks in Chains
Rejected bug bounty reports cost me real money, so I trained small specialised models to predict vulnerability chains like IDOR into privilege escalation. The synthetic data overfit, which turned out to be the lesson.
-
The Bug Hunter Toolkit: A Glimpse into AI-Accelerated Development
Building a bug bounty toolkit in three weeks with Google Gemini and Code Assist, after starting in the terminal and hitting the limits of a CLI. What worked, and where the AI lost the plot.