Offensive Security. Cloud Security. AI-Driven Defense.

Brandon Bennett logo

I’m Brandon Bennett — a cybersecurity analyst and penetration tester specializing in identifying and exploiting real-world vulnerabilities across modern web applications, APIs, and cloud environments.

What I Do

Offensive Security

Penetration testing across REST and GraphQL environments using Burp Suite, Nmap, Metasploit, and InQL. 30+ vulnerabilities identified and assessed using OWASP Top 10 methodologies — XSS, IDOR, CSRF, NoSQL injection, and access control flaws.

Cloud & Microsoft 365 Security

Microsoft 365 security and administration — Entra ID, Intune, Exchange, Defender, Purview — plus cloud security aligned with NIST, CIS, ISO 27001, SOC 2, and PCI-DSS frameworks.

GRC, Automation & AI

Governance, risk, and compliance — control design, documentation, and audit readiness. Automation and tooling in Python, PowerShell, and Golang, with AI and prompt engineering to enhance security workflows.

Selected Findings

  • GraphQL vulnerabilities enabling unauthorized admin account creation and remote device control
  • IDOR flaws exposing sensitive user data, including GPS and account metadata
  • 18+ XSS vulnerabilities caused by outdated JavaScript modules in production systems
  • Information disclosure and authentication weaknesses impacting user security

Explore my projects, read my tutorials and articles, or get in touch.

“You miss 100% of the shots you don’t take.” — Wayne Gretzky

— Michael Scott