HACKER
whoami
Offensive Security Consultant

KENT APOSTOL

Penetration Tester // Bug Bounty Hunter // VDP

Experienced offensive cybersecurity consultant with a proven track record in penetration testing, vulnerability assessments, and responsible disclosure across finance, healthcare, and government sectors — including NASA.

10+
Hall of Fames
13+
Certifications
$1K+
Bounties Earned
Kent Apostol
Available

Achievements

01
Elosoft
Security Consultant

While still a student in 2022, Elosoft offered a regular security consultant position after identifying and reporting critical vulnerabilities in their web application and assisting with full remediation.

Elosoft
02
BASF
CRLF Injection

Discovered a CRLF Injection vulnerability in BASF systems. The Germany-based chemical giant recognized the contribution by adding the name to their official Security Researcher Hall of Fame — "Heroes of BASF."

BASF
03
Informatica
CORS Vulnerability

Reported a Cross-Origin Resource Sharing (CORS) vulnerability in Informatica's systems. The Redwood City-based software company acknowledged the responsible disclosure by listing the name in their Hall of Fame.

Informatica
04
Liquid Pixels
Server Status Exposure

Discovered an exposed server-status page, exploiting it to monitor incoming requests and access sensitive endpoints used by clients. Liquid Pixels awarded a bug bounty of $250 for this finding.

Liquid Pixels
05
Hivelocity
Subdomain Takeover

Successfully executed a subdomain takeover attack against the Tampa, Florida-based hosting company Hivelocity. Rewarded with a $50 bug bounty for the responsible disclosure.

Hivelocity
06
Tecno Mobile
IDOR

Found an Insecure Direct Object Reference (IDOR) vulnerability in Tecno Mobile's application. The Shenzhen-based smartphone manufacturer awarded the Safe Keeper badge in recognition.

Tecno Mobile
07
MicroStrategy
Domain Takeover

Successfully took over one of MicroStrategy's domains, contributing to the security of the Tysons Corner-based software company. Rewarded with a bug bounty for the discovery.

MicroStrategy
08
2C2P
SQL Injection

Discovered and reported a SQL injection vulnerability in the Singapore-based global payments platform 2C2P. Received an official letter of appreciation from the company.

2C2P
09
CERT-WM
Responsible Disclosure

Responsibly disclosed a vulnerability to Het Waterschapshuis (CERT-WM), the central IT organization for Dutch water authorities. Listed in their Security Researcher Hall of Fame.

CERT-WM
10
NASA
Hall of Fame

Discovered and responsibly disclosed a vulnerability in NASA's digital infrastructure. Recognized in NASA's Security Researcher Hall of Fame and received a personal letter of appreciation from one of the world's most respected organizations.

NASA

Certifications

ISC²
Official ISC2 Certified in Cybersecurity (CC)
ISC2 Certificate
CIS
Cisco Networking Academy — Intro to Cybersecurity
CISCO Certificate
OPS
OPSWAT Academy — Intro to Critical Infrastructure Protection (ICIP)
ICIP Certificate
GGL
Foundations of Cybersecurity by Google
Google Certificate
TCM
The Cyber Mentor — Practical Ethical Hacking
PEH Certificate
C3SA
CWL Certified Cyber Security Analyst [C3SA]
C3SA Certificate
CAP
Certified AppSec Practitioner (CAP)
CAP Certificate
MCRA
Multi-Cloud Red Teaming Analyst (MCRA)
MCRA Certificate
CNSP
Certified Network Security Practitioner (CNSP)
CNSP Certificate
CCSP-AWS
Certified Cloud Security Practitioner — AWS (CCSP-AWS)
CCSP-AWS Certificate
CRTA
Certified Red Team Analyst (CRTA)
CRTA Certificate
ADRTS
Certified Active Directory Red Team Specialist (CADRTS)
ADRTS Certificate
CAPEN
Certified AppSec Pentester (CAPen)
CAPen Certificate

Contact

Email
Use the form to reach out directly
LinkedIn
Kent Shane Apostol
Location
Iloilo City, Western Visayas, Philippines
↓ Download Resume