Independent security research

I find the seams
before they split.

Michael Blake is a security researcher and bug bounty hunter exploring how modern web systems break—and helping teams fix them responsibly.

guest@recon.zip zsh

guest@recon.zip ~ % whoami

Michael Blake

security researcher / bug bounty hunter

status: looking closer

guest@recon.zip ~ %

Curiosity, applied
with intent.

I examine products from the outside in—following assumptions, edge cases, and unexpected interactions until the real attack surface comes into view.

The goal is straightforward: turn interesting behavior into clear, reproducible findings that help make systems safer.

name
Michael Blake
role
Security Researcher
mode
Bug Bounty
base
recon.zip

Where I look.

Web applications are systems of trust. I look for the places where that trust gets blurry.

A/01

Application logic

Unexpected state changes, broken workflows, and the gap between intended and actual behavior.

A/02

Trust boundaries

Authorization assumptions, identity transitions, and data crossing places it should not.

A/03

Attack surface

Quiet endpoints, overlooked integrations, and small details with outsized security impact.

A disciplined loop

Observe.
Question.
Verify.

  1. 01

    Map the surface

    Understand the product, its boundaries, and what it assumes to be true.

  2. 02

    Stress the assumptions

    Change context, sequence, identity, and input. Follow anything that behaves differently.

  3. 03

    Build the proof

    Reduce the behavior to a safe, repeatable path with clear impact and evidence.

  4. 04

    Disclose responsibly

    Report with precision, collaborate on remediation, and leave the system stronger.

recon.zip / end of line

Stay curious.
Look closer.

Back to top