Remmy9
Offensive security researcher. I find vulnerabilities that matter, build tools that help other researchers work faster, and write about what I learn along the way. This site is a collection of field notes, techniques, and writeups from real engagements.
Research
Web, API, and cloud security — finding chains, not just bugs.
Writeups
Detailed breakdowns of real vulnerabilities, from discovery to impact.
Tools
Scripts and workflows that make recon, testing, and reporting faster.
Background
I started in bug bounty programs, spending years hunting vulnerabilities across public and private platforms. That grind shaped how I think — find edge cases that scanners miss, chain low-severity issues into real impact, and communicate findings clearly.
Over time that evolved into full offensive security work. I've reported 15+ critical and high-severity findings across web applications, Active Directory environments, cloud infrastructure, and mobile platforms. Every engagement reinforces the same lesson: the most dangerous vulnerabilities aren't the most complex — they're the ones hiding in assumptions.
Connect
Find me on GitHub for tools and experiments, or on X for shorter notes and research updates.