Application Security Researcher
Focused on SAST, IAST, and practical open-source security tooling.
I work on program analysis for security: building static and interactive analysis tooling that scales to real codebases, and doing vulnerability research on the JVM.
- CAST Attack: Ghost Bits in Java — Black Hat Asia 2026 Briefings, Singapore (Review Board top must-see selection)
- Cross-language code property graphs — merging per-language CPGs into a single graph with cross-language edges, so taint flows survive a language boundary
- Interprocedural taint analysis — cross-file and cross-module propagation, FQN-exact call resolution, sink-rooted result aggregation
- LLM-assisted auditing with deterministic verdicts — models for naming and labelling, exploitability decided by an engine, not by a prompt
- Build-from-source verification — reconstructing a runnable target from its repository, then confirming findings with IAST, OAST, and sanitizer signals
- JVM vulnerability research — bytecode and runtime semantics, gadget chains, instrumentation
Role: Security researcher and tool builderPrimary Domains: SAST, IAST, program analysis, JVM securityPreferred Stacks: Java, Kotlin, Scala, Python, Go, Rust, TypeScriptEnvironment: Linux, Docker, HPC batch clusters (PBS)
CodeAuditAssistant — JetBrains code audit plugin: deep call-chain tracking, millisecond method/class search, prebuilt vulnerability sinks, decompiler and path finder.
vulhub/java-chains — Java vulnerability exploitation platform.
OWASP-Benchmark/BenchmarkJava — OWASP test suite for measuring the speed and accuracy of SAST, DAST, and IAST tools.




