Skip to content

Case Studies

Dive into my diverse range of projects, showcasing my expertise in software development, design, and dedication to delivering exceptional results.

AI image prompt — Ultra-realistic, eye-level photograph of a bright, minimalist modern product studio during the day. On a clean light-oak desk sit a flagship iPhone and an Android device side by side, both displaying a polished digital-health app UI with elegant cyan (#00e5ff) accent lines and a security audit overlay. Bright natural daylight from large windows, soft shadows, green potted plants, shot on Hasselblad, high-end professional commercial branding
Project 01

Mobile Application Penetration Testing

A comprehensive grey-box mobile application penetration test of a digital-health flagship app (VitalisCare, iOS & Android) handling protected health information. The engagement combined static analysis, dynamic instrumentation, and network interception to prove insecure local storage of auth tokens, an SSL-pinning bypass enabling full MITM of PHI traffic, and a hardcoded API key recovered via decompilation — then delivered Keychain/Keystore migration, hardened certificate pinning, and secrets management to achieve HIPAA-aligned launch readiness.

Explore Case Study
AI image prompt — Ultra-realistic, eye-level photograph of a bright, minimalist modern logistics command center during the day. Smiling engineers stand around a large glossy table where a premium tablet displays an elegant API endpoint threat map and shipment manifest dashboards with glowing violet (#7c3aed) accent lines. Floor-to-ceiling windows pour natural daylight across clean white workstations and green potted plants. Shot on Hasselblad, high-end professional commercial branding, no dark cyberpunk aesthetic
Project 02

API Penetration Testing

A comprehensive grey-box API penetration test of a global logistics provider (TransGlobe Logistics) spanning 600+ REST and GraphQL endpoints behind a unified gateway. The engagement uncovered and remediated a mass BOLA/IDOR exposure leaking customer shipment manifests, a GraphQL introspection leak chained with query batching to bypass rate limiting, and a blind boolean/time-based SQL injection in an undocumented legacy tracking endpoint — establishing object-level authorization, schema governance, and cost-aware query limits across the estate.

Explore Case Study
AI image prompt — Ultra-realistic, eye-level photograph of a bright, airy modern cloud-operations command center during the day. A sleek glass wall displays an elegant AWS multi-account architecture map and IAM access graph with glowing cyan (#00e5ff) accent lines. Bright natural daylight floods through floor-to-ceiling windows, two diverse cloud engineers in smart-casual attire collaborate at a clean white standing desk, potted greenery, shot on Hasselblad, high-end professional commercial branding, no dark cyberpunk tones
Project 03

Cloud Security Review

A comprehensive cloud security architecture review of a high-growth, AWS-native SaaS analytics platform (Stratuscale Analytics). The engagement uncovered and remediated a multi-account IAM privilege escalation path via overly permissive assumed roles, a public S3 bucket exposing Terraform state files containing hardcoded secrets, and internet-facing EC2 jump boxes — re-architecting the estate around least privilege, AWS Secrets Manager, strict Security Group rules, and continuous CIS AWS Foundations Benchmark alignment.

Explore Case Study
AI image prompt — Ultra-realistic, eye-level photograph of a bright, minimalist modern network operations center during the day. On a sleek glass desk, a premium widescreen monitor displays an elegant network topology map and asset risk matrix with glowing warm amber (#f59e0b) accent lines. Bright natural daylight pouring from large office windows, modern ergonomic chairs, neatly racked switches faintly visible behind glass, shot on Hasselblad, high-end professional commercial branding
Project 04

Network Vulnerability Assessment & Pentesting

A comprehensive internal and external network penetration test of a hybrid OT/IT manufacturing enterprise (NordForge Industries) following a merger. The engagement chained a forgotten external VPN endpoint with weak credentials into LLMNR/NBT-NS poisoning, NTLM relay, and an unpatched domain controller (ZeroLogon / Kerberoasting) to prove full Active Directory domain compromise — then delivered network segmentation, SMB signing enforcement, and legacy protocol teardown to prevent ransomware-scale impact.

Explore Case Study
AI image prompt — Ultra-realistic, eye-level photograph of a bright, minimalist modern conference room during the day. On the glossy marble table, a premium sleek tablet is open, displaying an elegant web application vulnerability matrix and security audit reports with glowing mint-green (#00ff88) accent lines. Bright natural daylight pouring from large office windows, modern office chairs, shot on Hasselblad, high-end professional commercial branding
Project 05

Web Application Penetration Testing

A comprehensive, grey-box web application penetration test of a high-throughput FinTech transaction platform (VeloCart FinTech). The engagement resolved critical vulnerabilities introduced by AI-assisted "Vibe Coding" tools, including a severe client-side price override, broken JWT auth middleware accepting alg: "none", and Stored XSS inside vendor feedback channels — hardening endpoints and establishing rigorous, CI-integrated schema validations.

Explore Case Study
AI image prompt — Ultra-realistic, eye-level photograph of a bright, minimalist executive office during the day. In the center, a sleek glass table features a premium holographic tablet showing an interactive AI model security dashboard with elegant rose-red (#f43f5e) telemetry graphs. Soft ambient daylight, high-end clean workspace interior, shot on Hasselblad, shallow depth of field, corporate premium theme
Project 06

AI & Machine Learning Pentesting

A deep-dive AI/ML penetration test of an autonomous customer-service LLM agent for a Series-B AI startup. Using the proprietary OpenClaw framework we executed 1,840 adversarial prompts across nine LLM attack classes, uncovered a multi-step system-prompt extraction jailbreak, an indirect prompt injection chain via summarised webpages, and a RAG-layer PII leak — then engineered constitutional guardrails, input sanitisation, and context-window isolation that reduced jailbreak success from 38.2% to 0.4%.

Explore Case Study
Sponsored Links

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning