Cybersecurity student in New Zealand. I work on cloud security — mostly AWS and Microsoft Entra ID — and I build tooling that makes security reviews faster and more repeatable.

Most of what ends up here is a writeup of something I built or broke: identity blast-radius analysis, permissions-boundary escapes, and experiments in using LLMs to do the tedious parts of a cloud posture review without turning into another noisy scanner. I care about findings that come with a proof of concept — a report that shows the exact call chain out of a permissions boundary, not a guess.

Languages

Java
C++
C
Python
PowerShell
Bash
Git

Working with

AWS IAMMicrosoft Entra IDProwlerBloodHound CEMITRE ATT&CKLinux

Elsewhere