About

Hello World !

I'm Kuromatae, a full time Bug Bounty Hunter !

What I enjoy the most is web exploitation, and especially getting past the things that are supposed to stop me: WAFs, reverse proxies, ...
I have a soft spot for access-control bugs and for turning almost nothing (a single header, an unvalidated id) into a nice chain that ends on a SSRF or a RCE. I'm far from knowing everything, but digging into an application until it gives up is one of my favorite hobbies :)

I decided to create this website in order to share my passion through some things like write-ups and tools :)

Work with me

On top of bug bounty, I'm available for freelance security work. If you need someone who actually breaks web apps for a living, top ranked across the main platforms, feel free to reach out :)

A couple of things I can do:

  • Web and API pentest, from a real attacker's point of view, with clear and actionable reports.
  • Bypass and access-control audits. That is really my thing.
  • Private bug bounty, continuous or time-boxed, on your scope.

You can find me on multiple platforms:

You can reach me at for collaborations, missions or private programs.