Penetration Testing
Hands-on web and environment testing with Kali Linux, Metasploit, and Burp Suite.
Initializing secure session
13+ years of self-taught offensive security experience — web app testing, bug bounty hunting, and real-world penetration assessments.
ShadeXploit
[ identity protected ]
I help organizations understand and reduce real-world risk by thinking like an attacker and building like an engineer.
I'm a self-taught cybersecurity practitioner with 13+ years of hands-on experience in web application security, penetration testing, and bug bounty hunting. Currently pursuing a Cybersecurity Specialist program at Waukesha Technical College with a 3.9 GPA.
Most recently I completed an internal penetration test at a mid-size law firm — an authorized AIDR engagement that uncovered multiple severe vulnerabilities across web apps and internal services. I work directly with dev teams to verify fixes and produce clear findings for both technical and non-technical stakeholders.
Outside of engagements I hunt bugs through public programs on HackerOne and coordinated disclosure, build recon and scanning automation tools, and continuously sharpen my skills toward a full-time red team role.
Years Self-Taught Experience
Independent Security Projects
Bug Bounties Reported
Pentest Engagements
Hands-on expertise across the attack lifecycle, backed by strong software engineering fundamentals.
Hands-on web and environment testing with Kali Linux, Metasploit, and Burp Suite.
Manual discovery and validation of impactful flaws including auth and logic issues.
Network scanning and defensive review with Nmap, Wireshark, and firewall validation.
Practical familiarity with GPG, VeraCrypt, and OpenSSL for secure workflows.
Independent coordinated disclosure across live programs with reproducible reports.
Security scripting and automation for recon and repeatable checks.
Linux and Windows security setup, baseline hardening, and operations support.
Early-stage scripting for administrative and security tasks.
Auto-loaded GitHub repositories plus selected highlight projects.
OffensiveAuthorized internal penetration test at a mid-size law firm. Discovered and reported multiple severe vulnerabilities across web apps and internal services with full remediation guidance.
ToolingOngoing authorized testing of web environments — discovery, manual exploitation, and dev-team remediation tracking.
ResearchBuilt scripts to automate vulnerability scanning and network reconnaissance, reducing manual recon time.
OffensiveIdentified and validated web vulnerabilities across live public programs, submitting reproducible PoCs via HackerOne and coordinated disclosure.
A few bounty reports across public programs, focused on practical impact and responsible disclosure.
HackerOne
Bugcrowd
Coordinated Disclosure
Independent
Technical deep dives, CTF walkthroughs, and coordinated vulnerability disclosures.
Walkthrough of a recent AIDR internal engagement — methodology, critical findings, and remediation approach. Details sanitized to protect client confidentiality.
How I structure recon sessions for bug bounty programs — tooling, automation scripts, and what to focus on for faster triage.
Practical guide to doing effective web application testing with free tools and a methodical OWASP-based approach.
Discussion is powered by GitHub Discussions.
Set Giscus env vars to enable comments.
Self-taught from the ground up — from independent study to authorized penetration tests and bug bounty work.
Mid-Size Law Firm (Authorized Engagement)
Independent
Self-Directed
Waukesha Technical College
Independent
No contact form, no spam, no backend maintenance. Reach out through social channels or request details privately.