Experience
Track record
I work discreetly. That is why I present verifiable areas of experience instead of confidential customer names.
Selected evidence of experience
The following evidence is publicly verifiable. Confidential customer projects, systems and findings remain protected.
Published TeamCity CVEs
- CVE-2025-54531: Path traversal when unpacking plugins on Windows with possible arbitrary file write (NVD entry).
- CVE-2024-56353: sensitive credentials and session information in TeamCity backups (NVD entry).
- CVE-2024-47950: stored cross-site scripting in backup settings (NVD entry).
- CVE-2024-47949: path traversal allowing a backup file to be written to an arbitrary path (NVD entry).
- CVE-2024-47948: path traversal exposing readable server files through the backup process (NVD entry).
These vulnerabilities demonstrate not only tool knowledge, but the entire chain from analysis and reproduction to impact assessment and responsible disclosure.
Public bug bounty track record
- EC-Council Bug Bounty Hall of Fame: named entry as Thomas Siegbert in 2023 for Responsible Disclosure.
- OTTO.de Bug Bounty on YesWeHack: publicly visible program activity under the handle
user0x1337; The YesWeHack Hunter profile is also linked.
These public postings demonstrate practical experience with real-world applications, reproducible reporting, and coordinated disclosure. Experiences from private programs are incorporated into my work, but are neither mentioned as customer references nor published with confidential details.
Technical publications
- ROP through a format string vulnerability: detailed exploit analysis with reverse engineering in a controlled lab environment.
- Why AI-generated bug bounty reports often fail: criteria for reproducible, impact-oriented findings.
- XSS Never Dies: technical analysis of why cross-site scripting remains practically relevant despite modern frameworks.
For more technical posts and CVE write-ups, see the blog. As a publicly verifiable open-source project, I develop and maintain htb-operator, a Python command-line tool for automating workflows on Hack The Box.
Example of an actionable deliverable
The full synthetic sample report shows how I structure overall risk, technical findings and subsequent decisions. It does not contain customer, contact or production data.
Typical areas of responsibility
Security assessments for digital products
I test web applications and APIs with understandable risk classification and prioritized recommendations for management, IT management and development.
Secure development and security reviews
I support teams in architectural decisions, threat modeling, code reviews and the integration of meaningful security checks into development processes.
Developer security training
I conduct practical security training for development teams. Using real attack patterns and findings, teams learn to identify risks earlier and deal with them effectively in everyday development.