
I’m Brandon Bennett — a cybersecurity analyst and penetration tester specializing in identifying and exploiting real-world vulnerabilities across modern web applications, APIs, and cloud environments.
What I Do
Offensive Security
Penetration testing across REST and GraphQL environments using Burp Suite, Nmap, Metasploit, and InQL. 30+ vulnerabilities identified and assessed using OWASP Top 10 methodologies — XSS, IDOR, CSRF, NoSQL injection, and access control flaws.
Cloud & Microsoft 365 Security
Microsoft 365 security and administration — Entra ID, Intune, Exchange, Defender, Purview — plus cloud security aligned with NIST, CIS, ISO 27001, SOC 2, and PCI-DSS frameworks.
GRC, Automation & AI
Governance, risk, and compliance — control design, documentation, and audit readiness. Automation and tooling in Python, PowerShell, and Golang, with AI and prompt engineering to enhance security workflows.
Selected Findings
- GraphQL vulnerabilities enabling unauthorized admin account creation and remote device control
- IDOR flaws exposing sensitive user data, including GPS and account metadata
- 18+ XSS vulnerabilities caused by outdated JavaScript modules in production systems
- Information disclosure and authentication weaknesses impacting user security
Explore my projects, read my tutorials and articles, or get in touch.
“You miss 100% of the shots you don’t take.” — Wayne Gretzky
— Michael Scott