Offensive security specialist. I break systems so they can be built stronger.
I'm B0dj0x — a cybersecurity researcher and red team operator focused on offensive security, bug bounty hunting, and vulnerability research.
Ranked in the Top 1% globally on TryHackMe, I specialize in discovering critical vulnerabilities across web applications, APIs, and network infrastructure. My work spans penetration testing, red team operations, OSINT, and full-chain exploit development.
I've reported vulnerabilities to major platforms including HackerOne, Bugcrowd, and YesWeHack, and I'm credited for discovering CVE-2025-0133 (Microsoft). I actively contribute to the security community through write-ups, CTF challenges, and open-source tools.
When I'm not hunting bugs, I'm building security tools, competing in CTFs, or teaching others how to think like an attacker — because understanding offense is the best defense.
Make the internet safer by finding and fixing vulnerabilities before malicious actors can exploit them. Every bug found is a system protected.
Key milestones in my cybersecurity journey.
Credited by Microsoft for discovering a critical vulnerability. Published advisory and proof-of-concept.
Achieved global ranking in the top 1% on TryHackMe, completing advanced offensive security paths and rooms.
Active hunter on HackerOne, Bugcrowd, and YesWeHack. Specializing in web application security and API testing.
Conducting full-scope red team engagements including social engineering, physical security, and network exploitation.
Building and maintaining open-source security tools including scanners, automation frameworks, and OSINT utilities.