Booking projects 4–8 weeks ahead
Manual pentesting across your attack surface
Martín Martín · Offensive security
Web, APIs, mobile, infrastructure, cloud and GenAI/LLM systems. You get reproducible findings, an engineering walkthrough and a retest.

19+Years in IT & security
1,000+Vulnerabilities reported
7Published CVEs
Engagements
Start with the system you need tested
I test applications, infrastructure and AI systems. Audit evidence and white-label delivery use the same technical process with different reporting and coordination.
Technical pentest
Web, APIs, mobile, infrastructure, cloud and GenAI/LLM. Report, walkthrough and retest included.
Evidence for an audit
A defined scope, control mapping and documented remediation evidence for ISO 27001, SOC 2 or NIS2 work.
White-label delivery
Technical execution for consultancies that retain the client relationship and commercial lead.
Evidence
Inspect the work before the call
Open the sample report, published research and source code before deciding whether to talk.
Research
Recent notes, tools and disclosures
Methods I use, vulnerabilities I reported and small tools I maintain. Public, with enough detail to inspect.
7.2
CVE-2026-44982HIGH
CWE-693·CrowdSec AppSec
WAF body-inspection bypass in the CrowdSec AppSec component: a request framed with chunked transfer encoding or HTTP/2 without a content-length reaches the backend with its body unscanned, defeating every body-matching rule.Bypass de la inspección de cuerpo del WAF en el componente AppSec de CrowdSec: una petición con Transfer-Encoding chunked o HTTP/2 sin content-length llega al backend con el cuerpo sin inspeccionar, saltándose todas las reglas que miran el cuerpo.
9.3
CVE-2026-39531CRITICAL
CWE-89·2K active installs
Unauthenticated SQL injection in the WP Directory Kit plugin allows attackers to inject arbitrary SQL through a request parameter that reaches the database layer without proper sanitization or prepared statements.Inyección SQL no autenticada en el plugin WP Directory Kit que permite a atacantes inyectar SQL arbitrario a través de un parámetro de la petición que llega a la capa de base de datos sin sanitización ni sentencias preparadas.
7.5
CVE-2026-39513HIGH
CWE-862·10K active installs
Broken access control in the Easy Appointments plugin allows unauthenticated attackers to reach a privileged REST route registered with '__return_true' as its permission_callback, exposing appointment data managed by the site.Control de acceso roto en el plugin Easy Appointments que permite a atacantes no autenticados acceder a una ruta REST privilegiada registrada con '__return_true' como permission_callback, exponiendo datos de citas gestionados por el sitio.
Contact
Send enough context to get a useful answer
The system, roles and target date are usually enough for a first reply. I normally answer within one working day.
- NDA available before sensitive scoping
- Madrid-based, working remotely worldwide
- Prefer a call? Book 30 minutes
For conferences or universities, use the direct speaking email.