Security Researcher · Reverse Engineer · Full-Stack Developer
I break apps to make them secure — and build things from scratch.
I bypass SSL/TLS certificate pinning at both Java layer and native C/C++ level.
Successfully bypassed:
Facebook · Instagram · Instagram Lite · Threads · Business Suite · TikTok · Twitter / X · Crunchyroll · CoinGlass · and many more across social media, streaming, and fintech apps.
APK Decompilation → Tear apart any Android app to its core
Native Library Analysis → .so file disassembly & ARM64 patching
Runtime Instrumentation → Frida hooks at Java & native levels
Smali Modification → Direct bytecode editing & APK rebuilding
Signature Spoofing → Bypass server-side signature verification
I intercept and reconstruct private/undocumented APIs from mobile applications — mapping authentication flows, documenting hidden endpoints, and turning closed systems into testable interfaces.
Frontend → Responsive websites with HTML5 · CSS3 · JavaScript
Backend → RESTful APIs with Python · Flask · FastAPI
Full Stack → End-to-end web applications from UI to database
| Security | Frida · Ghidra · Radare2 · Burp Suite · JADX · APKTool · Objection · mitmproxy |
| Languages | Python · JavaScript · Java · Kotlin · Smali · ARM64 Assembly |
| Web / API | HTML5 · CSS3 · REST APIs · Flask · FastAPI · Postman |
| Platforms | Android · Linux · Termux · Git |