Program analysis tools for hard-to-detect threats
Uncovering evasive threats and hard-to-find business logic vulnerabilities.
System & firmware security
Ph.D. student at CISPA Helmholtz Center for Information Security advised by Dr. Ali Abbasi. My work focuses on system and firmware security. Previously, I worked with AWS Proactive Security on a web vulnerability scanner for AWS-owned websites.
System security · Firmware analysis · Fuzzing · Web security
Uncovering evasive threats and hard-to-find business logic vulnerabilities.
Finding bugs below the OS in firmware, bootloaders, system management mode, and hardware-adjacent stacks.
Building automated systems that make deep security testing practical across large, real-world codebases.