$ whoami

I’m Adnan, a security engineer and researcher who likes learning about new ways to break software. My current focus has been CI/CD security and software supply chain attacks. You can find some of the open-source software I’ve developed on my GitHub!


I've had the fortune to present some of my research at well-known cybersecurity conferences such as Black Hat and DEF CON. In this blog, you'll find write-ups on the research I've done and bug bounties I've earned along the way.

For my day job, I work as a Security Engineer for a large company.

This is my personal blog and all articles here pertain to research I do on my own time. I’d appreciate if you do not associate me with my employer if you are citing this blog!

Certifications: OSCE3 | OSCP

My Passions

I’m most passionate about researching attacks that target systems used by developers. I used to be a back-end software engineer in a previous life, so I tend to have a good idea of where developers tend to cut corners during their day-to-day workflow.

My Background

I started off as a backend Software Engineer early on in my career. In 2019, I pivoted to offensive security, and I’ve found that I like breaking software a lot more than I like writing it.