Staff AI Security Researcher and Hacker
- burpference: A web application for identifying and reporting security vulnerabilities in Burp Suite
- stickyburp: A Burp Suite extension written in Kotlin that enables persistent sticky session handling in web application testing
- robopages: YAML based files for describing tools to large language models (LLMs), simplifying the process of defining and using external tools in LLM-powered applications
- DOMspy: A typescript-based extension for identifying and reporting security vulnerabilities in web applications
- dyana: A sandbox environment designed for loading, running and profiling various files including ML models, ELFs, Pickle, Javascript and more
- Redflag: AI-powered tool to determine high-risk code changes for security testing and PR review workflows
- OWASP Top 10 for LLM Applications: Community-driven effort to identify top security risks for large language model applications
- OWASP Top 10 for Large Language Model Applications - Core Team Technical Lead, Entry Lead Expert and Founder of the project
- Member of the BugCrowd Hacker Advisory Board
- OWASP Vancouver Chapter Lead
- OWASP Toronto Chapter Lead
- Defcon AppSec Village Volunteer
- MITRE Artificial Intelligence Working Group (AI WG)