~ / methodology
Methodologies
How I approach each kind of target — repeatable processes for web, AD, mobile, network, cloud, API, and full red-team operations.
Web Application
End-to-end methodology for testing web apps and APIs.
Active Directory
Enumerate, escalate, and move laterally through a Windows domain.
Mobile (iOS + Android)
Static and dynamic analysis for iOS and Android apps.
Network / Infrastructure
External and internal network penetration testing.
Cloud (AWS / Azure / GCP)
Assessing cloud identity, storage, and misconfigurations.
API
Testing REST, GraphQL, and other API surfaces.
Red Team Operations
Full-scope adversary emulation — tradecraft, infrastructure, and evasion.