ABOUT / dful

I'm Daniel Fulladosa, a pentester focused on offensive security. My work has included internal and web application pentesting, cloud security assessments, vulnerability scanning and assessments, and PCI DSS testing.

I started closer to systems and infrastructure, and I still like understanding how the pieces fit together before trying to break them. I've also built internal tools in Python and JavaScript when a repetitive part of the job was worth automating.

More recently, I've been spending a lot of time on AI and agentic systems: experimenting with models in offensive workflows, understanding how LLM applications are put together, and learning how to test the boundaries around tools, context, identity, and delegated actions.

This site is where I keep the useful parts of that work: notes I come back to and longer technical write-ups when something needs more room.