Professional Background

I’m a security researcher and application security engineer with a career spanning vulnerability research, web security, and security tooling development. I write about the vulnerabilities I discover and the tools I build to make application security more accessible to developers and security teams.

Experience

I’m a Senior Security Researcher on the Azure DevSec team at Microsoft (https://www.microsoft.com/), where I spend most of my time turning vulnerability disclosures into root-cause patterns and then hunting for variants of those patterns across frameworks, libraries, and service configurations. Lately that’s meant a lot of SSRF. Before Azure DevSec I was on MSRC’s Vulnerability & Mitigations team doing research on Microsoft cloud services.

Before Microsoft:

Independent Research

Outside of work I do source-level vulnerability research against widely deployed open-source software:

  • Kodi — found and patched a use-after-free in the texture cache. The fix was merged upstream and shipped in Kodi v22 “Piers” (PR #27972).
  • FFmpeg — reported use of uninitialized memory in the Escape 130 decoder (old_y_avg). Fixed and merged upstream, with the commit crediting me as the finder (PR #22568).
  • Additional reports still under coordinated disclosure.

Projects

  • csp-toolkit — A Python library and CLI for parsing, analyzing, and finding bypasses in Content Security Policy headers. Available on PyPI.
  • OutOfBits — An out-of-band application security testing platform where the callback response is programmable. DNS and HTTP callbacks run through a chain of Python modifiers you write yourself — DNS rebinding, fire-once tokens, conditional 401s on the SSRF target — executed in a five-layer sandbox.
  • appsec.fyi — A curated library of 6,800+ application security resources across 25 topics, organized by vulnerability class.

Community

  • Founded the OWASP Indianapolis Chapter in 2005 and still run it — 600+ members, quarterly meetings, and all the sponsor and speaker wrangling that goes with them.
  • Contribute code to OWASP ZAP (Zed Attack Proxy).

Presentations

  • Extending Burp @ DerbyCon, 2017 — Slides
  • Ruby and Security @ CircleCityCon, 2015 — Slides

Outside Work

I’m an avid runner and cyclist. I’ve completed a 30k, several half-marathons, and more 5k’s than I can count. Follow me on Strava.

Contact