Focused on real-world offense and defense — Web security, cloud security and agentic security.
Studying the weak points of target systems from an attacker's perspective — finding and proving issues before real risks materialize.
Research on attack surfaces and exploitation across major cloud providers — distilled into open-source tools like lc, cloudsword and CF.
Exploring the boundaries of AI agents in offense and defense — a full pipeline from structured knowledge to autonomous pentest agents.
Digging into source code to uncover security risks — eliminating vulnerabilities before they ship.