Skip to content
The XSS Rat

Independent offensive security · Maasmechelen, Belgium

I break web apps, APIs and mobile apps before somebody else does it for free.

Manual, business-logic-first penetration testing by a named researcher — not a scanner report with a consultancy logo on the front. Fourteen accepted findings at OpenAI, a place in Google’s hall of fame, and a report your developers can actually act on — scoped, tested and delivered inside one week.

0

Findings accepted at OpenAI

Fourteen separate vulnerabilities reported to and accepted by OpenAI.

Google

Honourable mentions

Listed in Google's Vulnerability Reward Program honourable mentions.

TOP 0

Intigriti, within one month

Reached the platform top 20 in a single month of hunting, then moved to client work.

0+ yrs

Teaching offensive security

One of the most-followed independent voices in application security.

What I test

Three surfaces, tested by hand.

Every engagement is fixed-price, fixed-date, and finished inside one week. You know the cost and the calendar before anything starts.

014 days · 5 for a large app

Web application

Authenticated, multi-role testing of the whole application — not a scanner report with a logo on it. Broken access control and business-logic abuse are where I spend most of the engagement, because that is where the findings that matter actually live.

  • Broken access control (IDOR, horizontal & vertical privilege escalation)
  • Business-logic and workflow abuse
  • Injection: XSS, SQLi, SSTI, XXE, command injection
  • Authentication, session handling and password-reset flows
  • SSRF, file upload and deserialisation
  • Tenant isolation in multi-tenant SaaS
OWASP WSTGPTES

From

€4,000

Scope it →
023 days

API

REST, GraphQL and gRPC, tested against the spec and then well beyond it. APIs fail on authorisation far more often than on injection, so every endpoint is exercised across every role — including the ones your documentation does not mention.

  • Object- and function-level authorisation (BOLA / BFLA)
  • Mass assignment and excessive data exposure
  • GraphQL introspection, batching and query-depth abuse
  • Rate limiting, resource consumption and enumeration
  • JWT, OAuth 2.0 and API-key handling
  • Undocumented, deprecated and shadow endpoints
OWASP WSTGPTES

From

€3,000

Scope it →
035 days · one full week

Mobile application

iOS and Android, tested on real devices. Static review of the binary, dynamic instrumentation at runtime, and full testing of the backend the app talks to — because a mobile app is mostly an API client wearing a nice interface. A single platform takes less; both fit inside the week.

  • Insecure local storage, keychain and keystore misuse
  • Certificate pinning bypass and traffic interception
  • Runtime instrumentation with Frida and Objection
  • Hardcoded secrets and reverse engineering of the binary
  • Deep links, IPC and exported component abuse
  • The backing API, tested to the same depth as a standalone API engagement
OWASP MASTGPTES

From

€5,000

Scope it →

How it runs

Five steps, no surprises.

The same process every time, whether it is a three-day API review or a full mobile engagement — structured on PTES, tested to OWASP's guides.

Methodology

Engagements are structured on the Penetration Testing Execution Standard (PTES), and the testing itself follows OWASP's Web Security Testing Guide and Mobile Application Security Testing Guide. That means the coverage is a published checklist rather than one tester's habits — you can read the standard and see exactly what was in scope.

PTES
Penetration Testing Execution StandardEngagement structure, end to end
OWASP WSTG
Web Security Testing GuideWeb application and API testing
OWASP MASTG
Mobile Application Security Testing GuideiOS and Android testing
01

Scope & rules of engagement

A 45-minute call to agree targets, roles, test accounts, out-of-scope systems and a testing window. You get a fixed price and a fixed date before anything starts — no hourly surprises. A 30% deposit on signature holds the dates.

02

Recon & mapping

Full attack-surface mapping: every endpoint, parameter, role and state transition. This is the phase most vendors rush, and it is the reason their reports read like a scanner's.

03

Manual exploitation

The bulk of the engagement. Automated tooling runs in the background for coverage, but every reported finding is manually verified and manually exploited. No unvalidated scanner output ever reaches your report.

04

Reporting

Each finding gets reproduction steps a developer can follow, a CVSS 4.0 score, real business impact in plain language, and a concrete fix. Plus a one-page executive summary that a non-technical board can read.

05

Debrief & free retest

A live walkthrough with your engineers to answer questions while the context is fresh. Once you have shipped fixes, I retest every finding free of charge within 90 days and issue an updated attestation letter.

See it before you buy itA complete sample engagement packThe full 21-page document a client receives: the approved test plan, seven worked findings with reproduction steps and CVSS 4.0 vectors, the WSTG coverage record showing what was tested and found clean, the retest results and the letter of attestation. Built around a fictitious client so nothing real is disclosed.Download the sample packPDF · 21 pages · OWASP WSTG v4.2 + PTES

Pricing

Published rates, fixed quotes.

Most security vendors hide their pricing so they can work out what you can afford. Here is mine.

Essential

One target, tested properly. Right for a startup heading into its first security review, or a single new feature that needs eyes on it before launch.

€2,000from · 2 days
  • One web app, one API or one mobile platform
  • Grey-box, single authenticated role
  • Full findings report with reproduction steps
  • Executive summary
  • Free retest within 90 days
Scope an Essential test
Most chosen

Professional

The engagement most clients actually need: the application and the API behind it, tested across every role, with the authorisation matrix fully exercised.

€4,000from · 4 days
  • Web app plus its backing API, or a full mobile platform
  • Multi-role, authenticated, full authorisation matrix
  • Business-logic and tenant-isolation testing
  • Findings report, executive summary, CVSS 4.0 scoring
  • Letter of attestation for your customers and auditors
  • Live remediation call with your engineers
  • Free retest within 90 days
Scope a Professional test

Continuous

For teams shipping every week. A standing engagement where each release gets looked at, rather than one annual audit that is stale by March.

€5,000per month · 12-month term
  • Five testing days every month — a full engagement week, rolled over up to 3 months
  • Unlimited retests, no 90-day window
  • Priority scheduling — 5 working days' notice
  • Direct Slack or Teams channel for your engineers
  • Quarterly attestation letters
  • Annual full-depth engagement at a 15% discount
Discuss a retainer
  • All engagements are fixed-price, quoted from a €1,000/day rate. You approve the scope and the number of days before any work starts.
  • No engagement runs longer than one week. If a target genuinely needs more than five days, it is two scoped engagements with a report after each — never an open-ended bill.
  • A 30% non-refundable deposit is payable on signature; it secures your testing window in the calendar. The balance falls due on delivery of the report, net 14 days.
  • Prices exclude 21% Belgian VAT. VAT is not charged on reverse-charge invoices to VAT-registered businesses outside Belgium.
  • Retesting beyond the included window, out-of-hours testing and on-site work are quoted separately.

Track record

Public, verifiable, and not a stock photo.

One client below is named with their permission; the rest of the client work stays under NDA. Everything else here is disclosed under the bug-bounty programmes' own rules, so every line is checkable.

Selected client

Poloniex

Cryptocurrency exchange

Named with permission. What was tested and what was found stay under NDA, as with every client.

OpenAI

14 findings

My own finding

Fourteen separate vulnerabilities reported to and accepted by OpenAI, including broken access control in a Tier 1 product that was reopened and escalated to P3 after new technical evidence.

Google

Hall of fame

My own finding

Listed in Google's Vulnerability Reward Program honourable mentions, with a report accepted into the programme and assigned to an internal engineer for fixing.

Intigriti

Top 20

My own finding

Reached the platform's top 20 within a single month of hunting — 562 reputation across 39 accepted submissions — then moved on to client engagements.

Greenhost

€2,000

Found by a hunter I coached

A hunter I coached landed the highest payout the programme had ever awarded, for a serious PII leak. The company published a blog post about the fix.

I wrote the certifications other people study for

Three professional certifications — web, API and network penetration testing — built from years of doing the work rather than from a syllabus. Alongside them, the hunters I coach have landed first triages at Google, P3s at OpenAI, and the largest payout a programme had ever made. Codifying a method well enough that other people can pass an exam on it, and then land real bugs with it, is a harder test of that method than only using it yourself. Your engagement gets the same method, from the person who wrote it.

  • Authored

    Website penetration testing

  • Authored

    API penetration testing

  • Authored

    Network penetration testing

The Endless Bundle$900$200one payment · yours forever2 seats at a timeTwo people in at a time, deliberately. I want to actually know the rats I am teaching, and that does not scale.45+ courses across web, API and business-logic testingThree certification paths, including CNWPPWeekly live sessionsEvery future release included — no subscriptionRatCTF also runs free Docker-based labs — 40 machines across 8 themed series, plus an OSEP track.See it on RatCTF

Questions

Before you ask

Forty-five minutes, no charge and no slide deck. You describe the application, who uses it and what would hurt most if it leaked; I ask enough questions to size the work honestly. You leave with a scope, a fixed price and a date. If penetration testing is not what you actually need yet, I will tell you that instead of selling you one.

Next step

Tell me what you have built.

A 45-minute call, no charge and no pitch deck. You describe the application, I tell you what testing it properly costs and how long it takes. If it is not worth doing, I will say so.

Based in

Maasmechelen, Belgium

Remote across the EU · on-site on request

Pick a slot directly in my calendar — no back-and-forth