RXDSEC
Loading0%
[ 00 ]  Index VAPT · Red Teaming · AI Security

RXDSEC/ENGINEER

Cybersecurity practitioner working in offensive security — VAPT, web application penetration testing, and AI red teaming. I build the tools that break things, then the tooling that makes breaking them repeatable.

Available for work 6 public repos MIT by default Scroll
2+
Years in security
0
Tools shipped in REX
0
Model providers wired
3OS
Platforms targeted
[ 01 ]

Introduction

Who

I'm rxdsec — a cybersecurity practitioner specialising in offensive security. Vulnerability assessment and penetration testing, web application security, and AI red teaming, grounded in the OWASP Top 10 including the one written for large language models.

The work runs across three things that keep turning out to be the same thing: breaking applications, investigating what happened after someone else broke one, and building the tooling that makes both repeatable instead of heroic.

How that plays out

Two-plus years of it: digital forensics on live investigations — evidence extraction, triage and reporting. Responsible disclosure of XSS, SQL injection and CSRF against production targets. Web application security testing end to end. And, currently, stress-testing LLM prompts and outputs across GPT, Claude and Gemini so unsafe model behaviour gets caught before it reaches production.

2+ years in security OWASP Top 10 OWASP Top 10 for LLMs Open to work
2+
Years in security
0
Public repos
0
Vuln classes disclosed
0
Tools shipped in REX
[ 03 ]

The flagship

REX

What it is

An offensive-security agent that also happens to be an excellent engineer. It fingerprints the stack, traces tainted input from source to dangerous sink, builds and encodes the payload, drives a real browser to prove it, then writes the patch and runs the test that closes it.

Why it matters

Nothing leaves the machine that you didn't send. Keys live in the OS credential store, sessions are append-only files on disk, and the hard safety denylist sits above the rule engine — so no setting and no persuasive prompt gets underneath it.

Discipline
Offensive security and software engineering, in one loop
Tools
42 executors across recon, exploitation, files, shell, network, browser and desktop control
Providers
23 — Anthropic, OpenAI, Gemini, Groq, DeepSeek, Ollama, LM Studio, llama.cpp and any OpenAI-compatible endpoint
Stack
Electron · React · TypeScript monorepo, agent core in the main process
Platforms
Windows · Linux · macOS
Telemetry
None
Licence
MIT
[ 04 ]

What I actually do

Offensive security — VAPT, web application penetration testing, and AI red teaming — grounded in the OWASP Top 10, including the one for LLMs. Finding a bug is the short part. The long part is the tooling that finds the next hundred.

01 / Offensive

Break it on purpose

Web application penetration testing and VAPT against the OWASP Top 10. Responsibly disclosed XSS, SQL injection and CSRF in live production applications through coordinated disclosure programmes.

02 / AI security

Red teaming the models

Jailbreak and prompt-injection testing, adversarial evaluation, and model security against the OWASP Top 10 for LLMs — plus the evaluation frameworks that catch unsafe output before it reaches production.

03 / Forensics

Evidence, not guesses

Digital evidence extraction and forensic analysis across live cybercrime investigations — evidence triage, log analysis, and email investigation down to SPF, DKIM and DMARC.

Offensive security

Penetration TestingVAPT Web App Security TestingOWASP Top 10 Bug BountyVulnerability Research

Tools

Burp SuiteOWASP ZAPNmap WiresharkMetasploit CodeQLSemgrep

AI security

AI Red TeamingPrompt Injection Jailbreak TestingAdversarial Testing OWASP Top 10 for LLMsAI Governance

Forensics & defence

Digital ForensicsEvidence Triage Log AnalysisSPF / DKIM / DMARC Phishing Detection

Scripting & platform

PythonBashLinux SQLREST APIs GitHub ActionsDockerAWS
[ 05 ]

Find me

The bio says it best — I may be slow to respond, but I do respond.