Erik Nilsson
Penetration testing student at IT-Högskolan, currently on Advanced Network Penetration Testing. I did a year of .NET web dev before switching over — I just really like breaking stuff.
Mainly digging into web AppSec, Active Directory, and building clean, reproducible PoCs. Big fan of utilizing modern AI tooling (Claude Code, Codex) to work faster and automate repetitive workflows, backed by strict manual verification.
Current Focus & Learning Areas
Core areas I am actively studying, practicing in labs, and targeting in bug bounties.
Web AppSec & Access Control
Focusing on core web vulnerabilities: IDORs, Broken Object Level Authorization (BOLA), session management flaws, authentication state transitions, and business logic omissions using Caido and modern testing workflows.
Active Directory & Internal Pentesting
Hands-on experience from penetration testing studies analyzing Active Directory environments, mapping attack paths with BloodHound & RustHound, evaluating Kerberos/LDAP misconfigurations, and privilege escalation vectors.
Source Code & .NET Application Analysis
Leveraging a foundation in .NET web development (C#, ASP.NET) to trace request lifecycles through codebases, spot subtle input validation misses, and understand how backend frameworks enforce authorization.
AI-Assisted Workflow & Reporting
Utilizing agentic tooling (Claude Code, Codex, OpenCode) as practical accelerators for code navigation, test harness construction, and script automation. Grounded in a verification-first mindset — treating AI output strictly as hypotheses that require rigorous manual validation, PoC confirmation, and standards-compliant reporting.
Bug Bounty Track Record & Valid Findings
An honest overview of my real-world triage history. In bug bounty, duplicates are proof of valid vulnerability detection — each report sharpens the methodology.
Hunting Real Production Targets
Actively hunting on competitive public and private programs. Multiple submissions have been triaged and confirmed as legitimate, reproducible vulnerabilities (duplicate status). In bug bounty, valid duplicates prove that the detection methodology is spotting real bugs in production — the current focus is closing the timing gap and hunting newly deployed features and changes.
Education & Skills
Academic training, self-directed security research, and technical toolkit.
Offensive Security / Penetration Testing Internship
Looking for a practical LIA (internship) placement as part of my Higher Vocational Education at IT-Högskolan. Eager to contribute to a penetration testing, red teaming, or application security team (Sweden or remote).
Two-year vocational programme specialized in offensive security and practical penetration testing.
Completed: Introduction to Penetration Testing · Networks and Network Security · Secure OS Configuration · Programming for Pen Testers · Hacking and Vulnerability Analysis · Active Directory · Application Security and Web Penetration Testing.
Current: Advanced Network Penetration Testing.
Upcoming LIA (Internship): November 2026 — June 2027.
Studied HTML/CSS, JavaScript, C#, ASP.NET and relational databases at an introductory level. Switched tracks to IT security after the first year — having practical insight into how web applications are built makes it much more intuitive to reason about how they break.
Operating a registered Swedish sole proprietorship for bug bounty earnings and independent IT consulting. Active on competitive public/private programs with rewarded findings and valid duplicates, and available for freelance consulting and security assessments alongside studies.
Contact
Feel free to reach out for collaboration, questions, or junior security opportunities.
Currently seeking an offensive security / penetration testing internship (LIA) for November 2026 — June 2027. Whether you have an open placement, want to discuss application security, or talk bug bounties, feel free to reach out directly via email or LinkedIn.
Registered sole proprietorship in Sweden for bounty income and IT consulting. Available for select freelance security assessments, code reviews, and IT consulting alongside studies.