Landing

Independent Application Security Research

Security research that starts in the code.

I’m Duy Tran, an application security researcher focused on source-code review, authorization boundaries, web/API security, and practical vulnerability validation. I work through authorized testing and coordinated disclosure.

What I do

Focused application security work for software teams.

Engagements are scoped around concrete attack surfaces and security questions rather than generic scanner output.

Secure Source-Code Review

Manual source-code review of security-sensitive code, with emphasis on authorization, data flow, trust boundaries, and exploitable implementation flaws.

Web & API Security Assessment

Targeted testing for broken access control, authentication weaknesses, business-logic flaws, unsafe file handling, and other application-layer risks.

Focused Security Review

Review of a feature, patch, architecture decision, or suspected vulnerability when a team needs a narrow technical answer instead of a broad assessment.

Research

Public evidence, not marketing claims.

My research archive documents public vulnerability disclosures, CVE write-ups, technical validation, and the reasoning behind security findings.

Method

Evidence-driven review from boundary to impact.

01

Scope the system

Identify assets, actors, attack surfaces, trust assumptions, and the security question being tested.

02

Trace boundaries

Follow attacker-controlled data through authentication, authorization, persistence, and sensitive sinks.

03

Validate behavior

Use controlled runtime testing and negative controls to distinguish reachable impact from suspicious code.

04

Deliver evidence

Document reproducible findings, affected boundaries, impact, and remediation guidance without unsupported claims.

Newsfeed

Latest research, write-ups, and notes.

The original blog feed stays here as the living stream of new research and learning posts.

View Archive

Security review

Need a focused review of your application or source code?

Send the product or repository context, technology stack, intended scope, and the security questions you want answered.

Authorized engagements only. Scope and testing boundaries are agreed before active security testing begins.

Support my research