About
Profile — background, expertise, and approach
Au Yi Xian is a senior-level penetration tester with strong experience across offensive security, vulnerability research, and application security assessments.
He specializes in identifying real-world security weaknesses across web applications, mobile applications, cloud environments, thick client applications, kiosk & lockdown environments, source code, APIs, wireless networks, and enterprise systems.
He approaches every engagement with the mindset of a real-world attacker, identifying exploit chains that automated tools consistently miss — from authentication bypass to privilege escalation to AI/ML model manipulation.
His approach combines practical exploitation knowledge, OWASP methodology, CREST-aligned testing practices, CVSS v3.1 / CVSS 4.0 risk scoring, and strong reporting discipline that communicates impact to both technical and executive audiences.
CREST-aligned penetration testing across web, mobile, cloud, and thick client applications using industry-standard methodologies.
Prompt injection, LLM abuse testing, RAG poisoning, model threat modeling, and AI agent authorization bypass.
Clear, actionable security reports with CVSS v3.1 / CVSS 4.0 scoring, business impact analysis, and developer-friendly remediation guidance.
Credentials Vault
Verified certifications — hover to authenticate
Security Testing Capabilities
Comprehensive offensive security testing across all attack surfaces
Web Application VAPT
- ›OWASP Top 10 testing
- ›Authentication & authorization bypass
- ›Business logic exploitation
- ›API security testing
- ›Injection flaws (SQLi, NoSQLi, XXE)
- ›Session management review
- ›XSS / CSRF / SSRF / IDOR / RCE
- ›JWT & OAuth vulnerabilities
- ›CORS misconfiguration
Mobile Application VAPT
- ›Android security testing
- ›iOS security testing
- ›Runtime analysis with Frida
- ›Reverse engineering (JADX/MobSF)
- ›Root / jailbreak detection bypass
- ›Sensitive data storage review
- ›API traffic interception (Burp)
- ›Deep link & intent exploitation
- ›Certificate pinning bypass
Source Code Review
- ›Manual secure code review (SAST)
- ›Authentication & authorization review
- ›Input validation analysis
- ›Cryptographic implementation review
- ›Insecure deserialization review
- ›Dangerous function identification
- ›Business logic flaw detection
- ›Secret / credential exposure
- ›Semgrep ruleset analysis
Cloud VAPT
- ›AWS security assessment
- ›IAM privilege escalation review
- ›S3 bucket permission analysis
- ›Network exposure mapping
- ›Security group misconfiguration
- ›Logging & monitoring gaps
- ›Cloud misconfiguration testing
- ›Secrets management review
- ›Container security (Docker/K8s)
Thick Client Testing
- ›Local storage & registry review
- ›Binary reverse engineering
- ›Traffic interception (Burp/Wireshark)
- ›Authentication flow analysis
- ›Hardcoded credential detection
- ›Memory analysis
- ›DLL hijacking review
- ›Anti-tampering bypass
Reverse Engineering
- ›Static analysis (Ghidra / IDA)
- ›Dynamic analysis & debugging
- ›Binary & PE inspection
- ›APK analysis (JADX / MobSF)
- ›Runtime instrumentation (Frida)
- ›Logic bypass analysis
- ›Obfuscation deobfuscation
- ›Malware behavior analysis
WiFi Penetration Testing
- ›Wireless encryption assessment
- ›Rogue AP / Evil Twin simulation
- ›WPA/WPA2 cracking
- ›PMKID attack
- ›Deauthentication testing
- ›Network segmentation review
- ›Client isolation bypass
Kiosk / Lockdown Breakout
- ›Kiosk escape & lockdown bypass
- ›Application restriction evasion
- ›Keyboard shortcut exploitation
- ›Task manager & process escalation
- ›Accessibility feature abuse (Sticky Keys)
- ›Virtual keyboard exploitation
- ›Registry & group policy bypass
- ›Multi-monitor display manager escape
- ›DLL hijacking in restricted environments
AI/ML Security Testing
- ›Prompt injection (direct & indirect)
- ›LLM jailbreaking techniques
- ›Model behavior manipulation
- ›AI application threat modeling
- ›RAG poisoning & context injection
- ›Data leakage via model output
- ›AI agent authorization bypass
- ›AI supply chain security
Testing Methodology
Structured engagement lifecycle — from reconnaissance to validated remediation
Reconnaissance
✓COMPLETEPassive and active information gathering — OSINT, asset discovery, technology fingerprinting, and attack surface enumeration.
Threat Modeling
✓COMPLETESTRIDE analysis, trust boundary mapping, data flow diagramming, and risk prioritization based on asset criticality.
Attack Surface Mapping
✓COMPLETEComprehensive enumeration of entry points — APIs, authentication flows, file upload handlers, and parameter analysis.
Vulnerability Discovery
EXECUTINGManual testing combined with automated scanning — prioritizing business logic, authorization, and injection vulnerabilities.
Exploitation Validation
EXECUTINGProof-of-concept development to confirm exploitability, assess real-world impact, and identify exploit chain opportunities.
Risk Assessment
PENDINGCVSS v3.1 / CVSS 4.0 scoring, business impact analysis, exploitability assessment, and prioritization for remediation.
Reporting
PENDINGExecutive summary and technical detail — clear findings with reproduction steps, screenshots, and business context.
Remediation Advisory
PENDINGDeveloper-friendly guidance with code examples, secure configuration references, and library-specific recommendations.
Validation Testing
PENDINGRe-testing verified fixes, regression testing of adjacent functions, and confirmation of remediation effectiveness.
› Validate every finding before reporting — no false positives.
› Think like an attacker, report like a consultant.
› Exploit chains amplify low-severity findings.
› Business impact matters more than technical severity alone.
› Remediations must be developer-friendly and actionable.
Decrypted Case Files
Classified engagement archive — click to expand file contents
Web Application VAPT
Mobile Application VAPT
Source Code Review
Cloud Security Assessment
Thick Client Assessment
Establish Secure Channel
Encrypted communication channels — select your preferred method
Connect for professional enquiries, consulting, and project collaborations.
View public repositories, tools, and open source security projects.
For confidential enquiries, vulnerability disclosures, and consulting requests.
● Currently available for security consulting, penetration testing engagements, and technical leadership opportunities.