Overview
How I work
- Agree scope and rules of engagement with the client before any testing begins
- Carry out reconnaissance and OSINT to map the attack surface
- Run vulnerability scanning with Nessus and Nmap, then verify findings manually
- Test web applications with Burp Suite, and WordPress sites with WPScan
- Analyse traffic with Wireshark where the engagement calls for it
- Report risk-rated findings in plain language, with practical remediation guidance






