Security specialist

DanialSobhani

Fleet hardening, incident reconstruction, evidence-linked decisions — dense signal, no clutter.

02.

Operational metrics

Every number links to evidence on this site.

In progress: PortSwigger Academy · HackerOne path

03.

Case studies

Problem → Detection → Action → Result. Employer names omitted.

01.

Full attack-chain reconstruction

Forensic reconstruction of a WordPress admin compromise that escalated to a reseller-level control-panel backdoor.

Read case study

02.

Critical panel auth-bypass incident response

CVSS 9.8-class hosting-panel authentication bypass: lockdown, session kill, service masking, and fleet-wide IoC sweep.

Read case study

03.

Slider-plugin webshell forensics

Slider-plugin vulnerability leading to webshell; confirmed and traced via security-monitoring logs.

Read case study

All case studies

04.

Projects

Real tooling for fleet and SOC workflows.

SentinelWatch

CVE watch that polls NVD and RSS, deduplicates findings, and alerts via Telegram/email when CVSS ≥ 9.0 or a fleet-relevance match fires — scheduled with systemd timers.

View on GitHub

cPanel-Patch-Radar

Control-panel patch awareness: tracks upstream cPanel/WHM advisories and surfaces missing or delayed patches across managed hosts.

View on GitHub

Xmlrpc-attacks

Research tooling and notes around WordPress XML-RPC abuse patterns: amplification, credential stuffing, and practical mitigations.

View on GitHub

WP Attack Detector

Lightweight WordPress attack detection: log parsing heuristics for brute-force, plugin probe storms, and suspicious admin-ajax / REST patterns.

View on GitHub

All projects

05.

Under the hood

Real tools and technologies in day-to-day work.

LinuxcPanel/WHMWordPressWAFModSecurityImunify360systemdBash/PythonNVD/CVE feedsTelegram alerts

06.

Security posture

Hand-rolled hardening — verifiable.

  • XML-RPC disabled
  • Security headers (CSP, HSTS, X-Frame-Options)
  • REST user enumeration blocked
  • WP version fingerprint removed
  • SVG uploads blocked
  • Generic login errors
  • File editor disabled
securityheaders.com
Verify live grade

06.

Contact

For security roles or select consulting — form or direct email.