Selected work
Things I built, broke, or defended
Academic and internship projects across the offensive stack, from a live aviation CTF I co-engineered at EUROCONTROL to honeypots, mobile pentesting and full security audits. Write-ups for several of these are in progress.
Aviation CTF for 113 players
Co-engineered a capture-the-flag competition themed around aviation systems, played by 113 participants from across the European aviation sector. Designing challenges is the inverse of solving them: every puzzle has to be unambiguous, solvable by the intended path, and resistant to unintended shortcuts.
Alongside the CTF: penetration testing of aviation systems and applications, plus R&D supporting aviation cybersecurity.
Full audit: company & pharmacy
End-to-end security assessment of two organisations: OSINT reconnaissance, technical penetration testing, a phishing simulation campaign, and a staff awareness survey. The human layer turned out to be the shortest path in, which is usually the case and rarely the part that gets budgeted.
Honeypot lab: red vs blue
Deployed honeypot servers with Kibana dashboards to capture and visualise attacker behaviour, then ran the exercise from both sides: attacking the infrastructure, and reading what the detection layer actually caught. The gap between the two is where most of the learning sits.
Deliberately vulnerable Android app
Built an Android application seeded with intentional flaws, designed as a training target for mobile penetration testing. Writing the vulnerabilities on purpose forces a precision that finding them never does: you have to know exactly why each one works.
Network & system pentest report
Complete audit of a network and its systems, documented as a professional pentest report with findings, risk ratings and a mitigation strategy. A finding nobody acts on is a finding wasted, so the report was written for the person who has to fix it, not for the person who found it.
Detailed write-ups are being published as I go. Read the blog or see the full profile.