whoami

Professional Kaputtmacher

Hi, I’m pok3. I’m a penetration tester and CTF player who spends most of his time analyzing applications or devices for vulnerabilities, to make the world and the software we rely upon everyday a tiny bit safer.

#What I do

I mostly work on web applications and embedded devices: finding the bug, understanding why it exists, and helping vendors fix it. These days I also play around with AI a lot: Understand its capabilities, figure out how we can efficiently use it for offensive security and how we can secure it.

#Why this blog

Writing things down is how I learn. Even if it is just a post-mortem of something I worked on, writing about it helps me remember how I approached a problem and often makes me notice details that I did not fully realize during the actual testing or research. Additionally, I have been compiling numerous write-ups over the years that I wish to disseminate to the security community.

Another goal of this blog is to openly discuss the current developments in AI. This field is moving incredibly fast, and sometimes it feels like we are not talking about it critically enough.

On one side, there are people who are extremely enthusiastic about AI. They seem to celebrate every new development and sometimes talk as if a complete transformation of the world is just around the corner. On the other side, there are people who believe AI is mostly a bubble that will eventually burst, potentially taking a large part of the market down with it.

I do not really have such a strong opinion either way. I can see the benefits of this technology, but I can also see its drawbacks and risks.

I want to use this space to explore these developments, hear other people’s perspectives, and discuss ideas openly.

#Contact

The quickest way to reach me is by email. For anything sensitive, like a vulnerability report, please use my PGP key.

$ grep -rl CVE- ~/disclosures | wc -l → 1

$ cat ~/trophies.log

4× national finalist & winner

Austrian Cyber Security Challenge

  1. 2026 national final (attack/defense ctf) 1st / 10
  2. 2025 national final (jeopardy ctf) 3rd / 4
  3. 2024 national final (jeopardy ctf) 3rd / 4
  4. 2023 national final (jeopardy ctf) 2nd / 4

$ history | tail

  1. 07-2023 - now IT/OT Security Specialist@ Limes Security GmbH

    Mainly penetration testing web applications, hardware and infrastructure.

  2. 09-2022 - 12-2022 Intern@ Limes Security GmbH

    Built a LEGO robot that utilizes OPC UA, first contacts with penetration testing & OSINT analysis