Welcome to My Page!
vahe@hackvector:~$ _
I'm Vahe, this is my personal site. I am a cybersecurity consultant with passion for ethical hacking, security research, and uncovering vulnerabilities before the bad guys do. Whether it's web, network security, or red teaming, I help businesses stay ahead of cyber threats.
Professional Certifications
Security services that move the needle
Focused, senior-led engagements with crisp reporting and actionable fixes.
Web Application Pentesting
Deep, manual testing beyond scanners - auth flows, business logic, and chained issues.
- OWASP ASVS-informed coverage
- Auth/session, access control, logic flaws
- API & file upload abuse, RCE paths
External Network Testing
Realistic perimeter attacks to map, prioritize and reduce your external risk.
- Attack surface enumeration
- Exposure & misconfiguration checks
- Credential & password hygiene tests
Social Engineering
Human-first testing - phishing, pretexting and reporting to uplevel resilience.
- Phishing campaigns & training
- Pretext design & metrics
- Executive/privileged user focus
Secure Code Review
Targeted, manual review to catch vuln classes scanners miss.
- AuthZ logic, data flows
- Injection, deserialization, crypto
- PR review & dev handoff
AI / LLM Security Testing
If your product uses AI chat, copilots, or “ask your data” features - I test how attackers can make it leak data or take unsafe actions.
- Data leakage & privacy risks
- Bypassing rules, guardrails, and access limits
- Abuse testing (spam, cost spikes, unsafe outputs)
API Security Testing
APIs are where real data lives. I test whether attackers can access other users’ data, bypass permissions, or abuse endpoints at scale.
- Broken access control & data exposure
- Authentication, tokens, and session weaknesses
- Rate limiting, business logic, and abuse paths
Why choose me instead of a big company?
With large vendors, you rarely control who actually performs your assessment. In many cases the work is staffed by juniors - or if you’re lucky, mid-level testers. Senior experts may exist there too, but being assigned one is a rare lottery.
When you work with me, you know exactly who you’re getting: the person doing the work is the person on the call - a highly experienced tester with OSCP, OSCE, eWPTX and 10+ years in the field.
- Manual-first testing, not just scanner output
- Business-logic and chained exploit focus
- Clear, prioritized remediation guidance
- Direct collaboration and fast retests
If you want certainty about the caliber of your assessor - and a report that actually moves the needle - work with the person you know, not a rotating bench.
Talk to me about your scope