Offensive Security · Red Team & Application Security · Toronto

I find the way in, then show you how far it goes.

Red team, web and API exploitation, and vulnerability research. I run red and purple team assessments for 20+ enterprise clients and operate Cobalt Strike and Havoc on engagements. On my own time I found a six-bug chain that gave root on any robot in a consumer robot fleet. I also co-organize DEFCON Toronto, where I find the researchers and presenters worth hearing.

120+
Validated vulnerabilities
6
CVEs filed with MITRE
20+
Enterprise clients tested
15+
Conference talks
What I Do

Most of my week is red team and penetration testing at White Tuque: web, API, mobile, internal and external networks, and cloud, for clients in fintech, insurance, manufacturing, and oil and gas across Canada and the US. I operate Cobalt Strike and Havoc on red team engagements and lead them from scoping and rules of engagement through reporting and retest. For a major Canadian insurer I built the red team and penetration-testing pipeline, with recurring adversary simulations and tabletop exercises, so their teams practise against realistic attack paths instead of waiting for an annual test.

Web applications are where I started and where I'm strongest. I specialized in GraphQL under Nick Aleks, author of Black Hat GraphQL, and I've reported 120+ validated vulnerabilities on Fortune 500 programs, mostly authorization bypass, IDOR, race conditions and business-logic chains. My favourite is a high-severity race condition in PayPal's checkout, where a payment could be confirmed before the funds were captured.

How I Work
01

Start where attackers start

Public web apps, SaaS and identity, and the internal apps everyone assumes are safe behind the perimeter. That's usually where the first foothold and the best pivot are.

02

Show how far it goes

A finding matters when you can show the path from entry to objective. I map it to MITRE ATT&CK and write it so engineers know what to fix and executives know why it matters.

03

Turn repeat problems into tools

When I hit the same problem twice, I build something. That's where my GraphQL schema generator, my Burp extension for unauthenticated endpoints, and Eidolon came from.

Where I've Worked
White Tuque, Offensive Security Specialist
Toronto · Oct 2024 to Present
Black-box and grey-box penetration tests, red team and purple team assessments for 20+ enterprise clients plus standalone engagements, across web, API, mobile, networks and cloud. Operate Cobalt Strike and Havoc C2 on red team engagements. Built the red team and penetration-testing pipeline for a major Canadian insurer, with recurring adversary simulations and tabletop exercises. Review AI and agentic workflows for prompt injection, insecure tool use and excessive permissions. Lead engagements end to end and mentor interns on the offensive team.
ASEC, Penetration Tester
Toronto · May 2024 to Oct 2024
Application, API and network assessments for fintech and financial-services clients across Canada, the US, Australia and Europe, specializing in API and GraphQL security under Nick Aleks, author of Black Hat GraphQL and former Head of Security at Robinhood. Wrote a custom Nuclei template for each finding so clients could regression-test the fix in their own CI/CD pipelines.
DEFCON Toronto (DC416), Co-organizer
Toronto · 2025 to Present
I find researchers and presenters, help them shape their talks and workshops, and program the monthly meetups for Toronto's security community, including the AI Fight Club workshop at Palo Alto Networks for 200+ practitioners. Also on the organizing committee for TASK, where I spoke in 2025 and 2026.
HackerOne, Security Researcher
Remote · Feb 2022 to Present
120+ validated vulnerabilities across Fortune 500 programs, including severe findings on PayPal, Airbnb, Sony, Booking.com and AT&T. Focus on authorization bypass, privilege escalation, race conditions and multi-step business-logic chains.
Research & Tools

Root on any robot in the Ecovacs Deebot fleet

I soldered onto the robot's UART, dumped the firmware, recovered cloud credentials and mapped the MQTT topic tree. The broker trusted whatever device identity a client claimed, and the robot ran incoming commands as root with no signature check, so any account could push a shell to anyone's robot. Six-bug chain, six CVEs filed with MITRE, disclosed under the vendor's Safe Harbor, and presented at BSides Toronto 2026.  Read the write-up  Talk page

graphql_sdl_generator

Rebuilds and extends a GraphQL schema from scattered .gql files into one SDL file you can load into your testing tools.  github.com/amir-hosseinpour/graphql_sdl_generator

API-Authentication-Checker

Burp Suite extension that replays your proxy history with Cookie and Authorization removed and flags the endpoints that still answer.  github.com/amir-hosseinpour/api-authentication-checker

Eidolon

Open-source (MIT) workspace that runs offensive security work with an AI agent in the loop: per-engagement isolation, scope tokens, a hash-chained audit log and three-tier command gating.  github.com/amir-hosseinpour/eidolon

Selected talks
Get in touch

Canadian permanent resident, based in Toronto. I speak English, Persian and Mandarin. Happy to talk whenever works for you.

amir.m.hosseinpour@gmail.com Resume (PDF) GitHub HackerOne profile