LAB_STATUS: OPERATIONAL

[ Security research ]
& /recon_playbooks

Public research on Android internals, malware analysis, web recon, and LLM bug bounty methodology — published at stackntrace.dev.

/WHOIS_USER

Research notes, reproducible playbooks, and isolated lab targets.

I publish as helllguest at stackntrace.dev — long-form posts on Android platform security, malware triage, exploitation, and web attack-surface analysis.

Recent work includes the Web Recon Playbook series and an LLM Bug Bounty Playbook. This domain hosts an authorized research lab for hands-on drills.

37+
Published Posts
4
Live Lab Hosts
/REPOS

Active Intelligence Projects

VIEW_ALL_CODE chevron_right
LIVE

stackntrace.dev

Security research blog — Android internals, malware analysis, reverse engineering, web recon playbooks, and LLM bug bounty methodology. Open source, no analytics.

Astro MDX MIT
security

Web Recon Playbook

Multi-part command-first series: fingerprinting, OIDC metadata, subdomain takeover, GraphQL surface testing, and ffuf/Nuclei active recon.

settings_input_component

apk-triage

CLI for fast Android APK triage — manifest, permissions, exported components, native libs, and suspicious strings before you open a disassembler.

STATUS: active
Python
AUTHORIZED

helllguest Research Lab

Isolated drill environment on this VPS — Juice Shop API targets, Keycloak OIDC flows, staging misconfigs, and static recon surfaces. Authorized testing only.

Docker Caddy Juice Shop
anoop@helllguest: ~/intel/active
add close
$ whoami
helllguest
$ ls -la ~/intel/active
drwxr-xr-x 5 user group 4096 May 12 10:24 stackntrace
drwxr-xr-x 3 user group 4096 Apr 20 14:15 web-recon-playbook
drwxr-xr-x 8 user group 4096 Jan 05 22:40 apk-triage
drwxr-xr-x 4 user group 4096 Jun 18 09:12 helllguest-lab
$ ./status_check --verbose
[*] Checking lab hosts...
[+] lab-api, lab-auth, lab-staging: reachable
[+] TLS terminated by Caddy (Let's Encrypt).
$
STATUS: CONNECTED • ED25519_VERIFIED
/REMOTE_SHELL

Interact with the core.

Live status for the authorized research lab on this host. Targets run in Docker behind Caddy with Cloudflare at the edge.

check_circle Edge proxy: Cloudflare
check_circle Identity: Keycloak (lab-auth)
check_circle API target: Juice Shop (lab-api)
bug_report
/CONTACT

Found a bug? Or want to collaborate?

For security disclosures, professional inquiries, or research partnerships, reach out via the secure channels below.

mail
Email Address
key
Blog contact