I will run an external attack surface scan and report for your business

United States

I speak English, Spanish

External Attack Surface and Security Researcher

Freelance security researcher with 10 years of enterprise networking experience plus active bug bounty work on HackerOne. Confirmed, paid findings include a Deutsche Telekom OAuth misconfiguration (CV...
About this Gig

explanations

  • Know what an attacker sees before t exposure before it becomes an incident.hey find it first.


I run an external attack surface assessment on your company's public-facing footprint - domains, subdomains, exposed services, misconfigured APIs, leaked credentials, and outdated software - and hand you a plain-English report with prioritized fixes.


This isn't a generic vulnerability scanner PDF. I manually verify every finding before it goes into your report, so you're not chasing false positives.


Why trust this: I'm an active bug bounty researcher on HackerOne with confirmed, paid findings against major companies, including an OAuth redirect misconfiguration in Deutsche Telekom's infrastructure (CVSS 8.2), a stored XSS vulnerability (CVSS 6.1), and an exposed API discovered in Airbus's systems. I bring the same methodology I use against enterprise targets to your business.


What you get:

  • Full inventory of your external attack surface (domains, subdomains, IPs, open ports, exposed services)
  • - Identification of outdated or vulnerable software versions, exposed admin panels, misconfigured cloud

Server:

DNS

Web server

Operating system:

Windows

Linux