Professional Background
I’m a security researcher and application security engineer with a career spanning vulnerability research, web security, and security tooling development. I write about the vulnerabilities I discover and the tools I build to make application security more accessible to developers and security teams.
Experience
I’m a Senior Security Researcher on the Azure DevSec team at Microsoft (https://www.microsoft.com/), where I spend most of my time turning vulnerability disclosures into root-cause patterns and then hunting for variants of those patterns across frameworks, libraries, and service configurations. Lately that’s meant a lot of SSRF. Before Azure DevSec I was on MSRC’s Vulnerability & Mitigations team doing research on Microsoft cloud services.
Before Microsoft:
- Proofpoint — Staff Product Security Engineer, 2018–2022 — https://proofpoint.com/
- Salesforce — Senior Product Security Engineer, 2014–2017 — https://www.salesforce.com/
- Teradata — Principal Engineer, Application Security, 2012–2014 — https://www.teradata.com/
- Anthem (then WellPoint) — Information Security Advisor, 2011–2012 — https://www.antheminc.com/
Independent Research
Outside of work I do source-level vulnerability research against widely deployed open-source software:
- Kodi — found and patched a use-after-free in the texture cache. The fix was merged upstream and shipped in Kodi v22 “Piers” (PR #27972).
- FFmpeg — reported use of uninitialized memory in the Escape 130 decoder (
old_y_avg). Fixed and merged upstream, with the commit crediting me as the finder (PR #22568). - Additional reports still under coordinated disclosure.
Projects
- csp-toolkit — A Python library and CLI for parsing, analyzing, and finding bypasses in Content Security Policy headers. Available on PyPI.
- OutOfBits — An out-of-band application security testing platform where the callback response is programmable. DNS and HTTP callbacks run through a chain of Python modifiers you write yourself — DNS rebinding, fire-once tokens, conditional 401s on the SSRF target — executed in a five-layer sandbox.
- appsec.fyi — A curated library of 6,800+ application security resources across 25 topics, organized by vulnerability class.
Community
- Founded the OWASP Indianapolis Chapter in 2005 and still run it — 600+ members, quarterly meetings, and all the sponsor and speaker wrangling that goes with them.
- Contribute code to OWASP ZAP (Zed Attack Proxy).
Presentations
Outside Work
I’m an avid runner and cyclist. I’ve completed a 30k, several half-marathons, and more 5k’s than I can count. Follow me on Strava.
Contact
- Email: carl.sampson@gmail.com
- LinkedIn: carlsampson
- GitHub: sampsonc
- X: @chs
- GPG Key: View public key