ETHICAL HACKER · SECURITY RESEARCHER

I find weaknesses before they become incidents.

Security researcher focused on web security, cloud environments, threat analysis, and practical defensive improvements.

View Security Work
identity.yml
name: Nullshade
role: Security Researcher
location: Southeast Asia
focus: [Web, Cloud, AppSec]
status: Open to selected projects
auth_check.py
# Verify token integrity
def validate_session(req):
  token = req.headers.get('Authorization')
  if not token:
    return False
bash - 80x24
Focus Web Security
Current Cloud Security Research
CTFs 42 Completed
Reports 18 Responsible Disclosures

Curious by nature. Defensive by principle.

I am a security researcher who studies how systems fail, testing applications responsibly to help teams reduce real-world risk. My approach is grounded in the belief that effective security requires deep technical understanding combined with clear, actionable communication.

Whether I'm analyzing complex authentication flows, reviewing cloud IAM configurations, or hunting for logic flaws in web applications, I focus on documenting findings clearly and providing pragmatic remediation advice.

I value responsible disclosure, continuous learning, and building robust defensive controls.

sys_metrics
Uptime: Active
Specialty: AppSec, Threat Analysis
Approach: Assume Breach, Defense in Depth
Objective: Minimize Attack Surface

Security Capabilities

Technical focus areas and defensive competencies.

Web Security

  • Authentication Review
  • Authorization Testing
  • Session Security
  • Input Validation
  • Security Headers
  • API Security

Cloud Security

  • IAM Review
  • Configuration Assessment
  • Exposure Review
  • Logging & Monitoring
  • Least Privilege

Infrastructure

  • Linux
  • Docker
  • Networking
  • Web Servers
  • TLS
  • Reverse Proxies

Defensive Analysis

  • Log Analysis
  • Threat Modeling
  • Incident Triage
  • Vulnerability Management
  • Security Hardening
TOOLKIT:
Burp Suite Wireshark Nmap Linux Docker Git OWASP ZAP SIEM

Featured Security Projects

Practical tools, environments, and visualizations.

monitoring_dash.svg
Defensive Tools

Sentinel View

Security monitoring dashboard for reviewing alerts and asset status across environments.

HTML/CSSJSVisualization
auth_demo.svg
Web Security / Labs

AuthGuard Lab

Demo application exploring secure authentication and authorization patterns, highlighting common pitfalls.

PythonJWTOAuth
log_lens.svg
Defensive Tools

LogLens

Frontend visualization for analyzing fictional security events and identifying anomaly patterns.

Vanilla JSD3.js
cloud_posture.svg
Cloud

CloudCheck

Cloud security checklist and posture-review interface for rapidly auditing IAM configurations.

Audit ToolsSecurity Config
headers_scan.svg
Web Security

HeaderScan UI

Educational interface showing recommended web security headers and explaining their defensive benefits.

HTTP HeadersCSP
incident_time.svg
Research

Incident Timeline

Interactive visualization for documenting incident-response steps and tracking lateral movement patterns.

ForensicsVisualization

Security Labs

Safe local environments used for learning and testing defensive concepts.

Broken Auth Lab

Focus: Authentication mistakes and secure remediation strategies.

Access Control Lab

Focus: Understanding authorization logic and implementing robust defensive fixes.

API Security Lab

Focus: Secure API design, rate limiting, and strict input validation.

Logging Lab

Focus: How useful logging improves incident detection and speeds up triage.

CTF & Challenges

Fictional achievements demonstrating technical problem-solving.

42 Total Solved
12 Web
9 Forensics
8 Crypto
7 OSINT

Web Fortress

SOLVED
Category: Web Diff: Hard

Hidden Signal

SOLVED
Category: Forensics Diff: Medium

Cipher Trail

SOLVED
Category: Crypto Diff: Medium

Open Source Hunt

SOLVED
Category: OSINT Diff: Easy

Experience

2025 — Present

Security Researcher

Fictional SecOps Inc.

  • Review application security
  • Document vulnerabilities
  • Support remediation
  • Perform threat modeling
  • Improve defensive controls
2023 — 2025

Junior Security Analyst

Defiant Networks

  • Analyze alerts
  • Review logs
  • Support incident investigations
  • Track remediation
2021 — 2023

Systems / Web Developer

TechBuild Studio

  • Build web applications
  • Maintain Linux environments
  • Improve application security

Certifications

Security+

CompTIA (Placeholder) · 2024
View Credential →

eJPT-Style Fundamentals

Demo Security (Placeholder) · 2023
View Credential →

Cloud Security Fundamentals

Cloud Org (Placeholder) · 2023
View Credential →

Incident Response Basics

Defensive Inst. (Placeholder) · 2022
View Credential →

Responsible Disclosure

Security research should improve systems, not harm them.

  • Test only with explicit permission
  • Minimize operational impact
  • Protect sensitive user data
  • Report clearly with replication steps
  • Allow sufficient time for remediation

Research Notes

Articles on defensive engineering, architecture, and threat analysis.

Defensive Engineering Oct 12, 2025

What Good Security Logging Looks Like

An exploration of what fields matter most during an incident and how to standardize logs across microservices.

Read Write-up
Application Security Sep 28, 2025

Common Authentication Design Mistakes

Reviewing frequent architectural flaws in custom authentication flows and how to migrate to standard patterns.

Read Write-up
Cloud Security Aug 15, 2025

Why Least Privilege Matters in Cloud

A deep dive into IAM misconfigurations and how excessive permissions lead to unnecessary lateral movement.

Read Write-up
Incident Response Jul 02, 2025

Building a Better Incident Timeline

Methodologies for structuring logs and telemetry into a cohesive timeline during the first critical hours of triage.

Read Write-up

Dashboard

Current Research Cloud Identity
Open Labs 3
Write-ups 12
CTF Score 4,820
Latest Activity Reviewed authentication flows for Lab-02. Status: Secure.

"Clear findings, practical remediation advice, and strong communication throughout the review."

— Engineering Lead, Placeholder Corp

Interactive Interface

nullshade@portfolio:~
Welcome to Nullshade OS v1.0.0
Type "help" for a list of available commands.
Note: This is a safe, sandboxed simulation.
$

Let's talk security.

Available for selected security reviews and research collaborations.

CURRENT STATUS

Available for collaborations.

  • Web Application Review
  • Cloud Security Review
  • Security Architecture Feedback
  • Defensive Security Consulting

SECURITY CONTACT

PGP Key (Demo):
ABCD 1234 EFGH 5678 IJKL 9012 MNOP 3456
Placeholder data for portfolio purposes.