Red team, web and API exploitation, and vulnerability research. I run red and purple team assessments for 20+ enterprise clients and operate Cobalt Strike and Havoc on engagements. On my own time I found a six-bug chain that gave root on any robot in a consumer robot fleet. I also co-organize DEFCON Toronto, where I find the researchers and presenters worth hearing.






Most of my week is red team and penetration testing at White Tuque: web, API, mobile, internal and external networks, and cloud, for clients in fintech, insurance, manufacturing, and oil and gas across Canada and the US. I operate Cobalt Strike and Havoc on red team engagements and lead them from scoping and rules of engagement through reporting and retest. For a major Canadian insurer I built the red team and penetration-testing pipeline, with recurring adversary simulations and tabletop exercises, so their teams practise against realistic attack paths instead of waiting for an annual test.
Web applications are where I started and where I'm strongest. I specialized in GraphQL under Nick Aleks, author of Black Hat GraphQL, and I've reported 120+ validated vulnerabilities on Fortune 500 programs, mostly authorization bypass, IDOR, race conditions and business-logic chains. My favourite is a high-severity race condition in PayPal's checkout, where a payment could be confirmed before the funds were captured.
Public web apps, SaaS and identity, and the internal apps everyone assumes are safe behind the perimeter. That's usually where the first foothold and the best pivot are.
A finding matters when you can show the path from entry to objective. I map it to MITRE ATT&CK and write it so engineers know what to fix and executives know why it matters.
When I hit the same problem twice, I build something. That's where my GraphQL schema generator, my Burp extension for unauthenticated endpoints, and Eidolon came from.
I soldered onto the robot's UART, dumped the firmware, recovered cloud credentials and mapped the MQTT topic tree. The broker trusted whatever device identity a client claimed, and the robot ran incoming commands as root with no signature check, so any account could push a shell to anyone's robot. Six-bug chain, six CVEs filed with MITRE, disclosed under the vendor's Safe Harbor, and presented at BSides Toronto 2026. Read the write-up Talk page
Rebuilds and extends a GraphQL schema from scattered .gql files into one SDL file you can load into your testing tools. github.com/amir-hosseinpour/graphql_sdl_generator
Burp Suite extension that replays your proxy history with Cookie and Authorization removed and flags the endpoints that still answer. github.com/amir-hosseinpour/api-authentication-checker
Open-source (MIT) workspace that runs offensive security work with an AI agent in the loop: per-engagement isolation, scope tokens, a hash-chained audit log and three-tier command gating. github.com/amir-hosseinpour/eidolon
Canadian permanent resident, based in Toronto. I speak English, Persian and Mandarin. Happy to talk whenever works for you.