Web application security tester with a background in photography, colour science and UX/UI design. I look at applications from two sides: how they are meant to be used, and how they can be abused.
Photography and digitization work with museums and academic publications.
📍 Poland · 🎯 Web app pentesting, purple team · 🇵🇱 Chętnie porozmawiam po polsku
- Burp XSS Generator — Burp Suite extension for XSS testing. (Dopisz tu 1 zdanie: co dokładnie generuje i w jakich kontekstach.) For authorized testing only.
- Home security monitoring — Wazuh SIEM collecting events from my home devices.
- Password Strength Checker (in progress, repo coming soon) — Local app for password entropy, offline crack-time estimates, HIBP k-anonymity checks and a PQC-safe password generator.
- Syria wells prototype (PWA) — Prototype of a lightweight, offline-first web app for mapping and reporting the status of water wells in conflict-affected areas. Designed for field use with unstable connectivity and low-end mobile devices.
- ColorChecker Delta E — Streamlit app for Delta E calculation, used in my professional colour work.
- Light geometry — Pre-capture planning tool for reprographic setups (digitization, flat art photography and colour target workflows).
- Testing: Burp Suite, ffuf, Nmap, OWASP ZAP, Wireshark
- Code & automation: Python, Bash, JavaScript
- Environment: Linux, Docker, Git, Wazuh, Cloudflare
- TryHackMe (Top 1% globally) — completed paths: Web Application Pentesting, Web Application Red Teaming, Red Teaming, AI Security, SOC Level 1.
- PortSwigger Web Security Academy — in progress, currently XSS labs.
- Sekurak Websecurity Master — starting in November.
- Approach: I prefer understanding a vulnerability deeply over collecting badges quickly.
e-mail Feel free to reach out!