At White Band Associates, I conducted web application penetration tests on live production and staging environments using OWASP Top 10 and PTES methodologies. I identified and exploited vulnerabilities including SQL injection, XSS, IDOR, and SSRF.
I delivered reports with CVSS v3.x severity scores, proof-of-concept steps, risk analysis, and remediation guidance. I also mapped attacker techniques and tactics to the MITRE ATT&CK framework in assessment reports.
In controlled environments, I performed Active Directory enumeration and attack path analysis, then tested credential harvesting, Kerberoasting, and privilege escalation across Windows and Linux targets.
I developed a Python-based domain vulnerability scanner that combines reconnaissance, scanning, and OWASP Top 10 detection. Its severity classification and structured reports helped reduce manual reconnaissance time by 60%.

