Break it on purpose
Web application penetration testing and VAPT against the OWASP Top 10. Responsibly disclosed XSS, SQL injection and CSRF in live production applications through coordinated disclosure programmes.
Cybersecurity practitioner working in offensive security — VAPT, web application penetration testing, and AI red teaming. I build the tools that break things, then the tooling that makes breaking them repeatable.
I'm rxdsec — a cybersecurity practitioner specialising in offensive security. Vulnerability assessment and penetration testing, web application security, and AI red teaming, grounded in the OWASP Top 10 including the one written for large language models.
The work runs across three things that keep turning out to be the same thing: breaking applications, investigating what happened after someone else broke one, and building the tooling that makes both repeatable instead of heroic.
Two-plus years of it: digital forensics on live investigations — evidence extraction, triage and reporting. Responsible disclosure of XSS, SQL injection and CSRF against production targets. Web application security testing end to end. And, currently, stress-testing LLM prompts and outputs across GPT, Claude and Gemini so unsafe model behaviour gets caught before it reaches production.
Six public repositories and one flagship. Stars, licences and dates are straight off the GitHub profile — the descriptions are mine, because GitHub's are empty.
An offensive-security agent that also happens to be an excellent engineer. It fingerprints the stack, traces tainted input from source to dangerous sink, builds and encodes the payload, drives a real browser to prove it, then writes the patch and runs the test that closes it.
Nothing leaves the machine that you didn't send. Keys live in the OS credential store, sessions are append-only files on disk, and the hard safety denylist sits above the rule engine — so no setting and no persuasive prompt gets underneath it.
Offensive security — VAPT, web application penetration testing, and AI red teaming — grounded in the OWASP Top 10, including the one for LLMs. Finding a bug is the short part. The long part is the tooling that finds the next hundred.
Web application penetration testing and VAPT against the OWASP Top 10. Responsibly disclosed XSS, SQL injection and CSRF in live production applications through coordinated disclosure programmes.
Jailbreak and prompt-injection testing, adversarial evaluation, and model security against the OWASP Top 10 for LLMs — plus the evaluation frameworks that catch unsafe output before it reaches production.
Digital evidence extraction and forensic analysis across live cybercrime investigations — evidence triage, log analysis, and email investigation down to SPF, DKIM and DMARC.
The bio says it best — I may be slow to respond, but I do respond.