02 / Field Notes

About Me

I'm a 17-year-old independent bug hunter and security researcher. I spend my time reading requests, tracing trust boundaries, and looking for the moment an application believes the wrong thing.

I hunt on HackerOne and build my own tools when a workflow needs more precision. API hunting and source-code hunting are my favorite places to work: one shows me what an application says, the other shows me what it assumes.

When I'm not testing, I'm writing detailed reports, studying how systems fail, and turning small signals into evidence that developers can act on.

Just a hacker who doesn't understand anything without hacking.

rh2-1 / local terminalonline

Toolkit / Curiosity

Skills & Technologies

The tools change. The questions stay sharp.

API Security Research

01

Tracing trust breaks through request and response flows.

RESTGraphQLAuth

Source Code Review

02

Following assumptions from code to the security boundary.

ReviewLogicFlow

Web Application Security

03

Testing the places where identity, access, and state meet.

IDORAccessLogic

Reconnaissance & Attack Surface Mapping

04

Turning small signals into a clear attack-surface map.

ReconOSINTMapping

Security Automation

05

Building focused tools for repeatable, careful research.

ScriptsToolsData

Vulnerability Reporting

06

Making technical findings useful for the people fixing them.

PoCImpactFixes

Field journal — vol. II

Writeups

Security research is rarely about the obvious path. I examine how applications authenticate users, enforce authorization, and handle state — then turn reproducible behavior into clear, actionable findings.

Entries: 05
Status: curated
Clearance: public