01

IDENTITY / TRIFFIN AUGUSTINE

Behind the
handle.

Penetration tester. Bug bounty hunter. Security researcher. A curiosity problem that turned into a career path.

Triffin Augustine (TrffnSec)
TRIFFIN AUGUSTINE AKATRFFNSEC
ORIGIN

CURIOUS / BY DEFAULT

I like finding the part of a system that doesn't behave.

I'm Triffin Augustine, widely known in the security community as TrffnSec. I'm a penetration tester, bug bounty hunter, and security researcher with a strong passion for discovering real-world vulnerabilities and helping organizations strengthen their security posture.

My journey into ethical hacking started from pure curiosity and evolved into a professional pursuit as I began hunting vulnerabilities across public and private bug bounty programs. Over time, I've identified and responsibly disclosed security issues including XSS, Host Header Injection, IDOR, access control flaws, and logic vulnerabilities across well-known platforms, universities, and enterprise applications.

Today, I document findings through detailed write-ups on Medium, sharing attack paths, methodologies, and lessons learned. Alongside hunting, I focus on continuous learning, tool development, and community knowledge-sharing - practical, experience-driven security research is the whole point.

WEB SECURITYRECONBUG BOUNTYTOOLINGTRAINING
PROOF

RESPONSIBLE DISCLOSURE / ACKNOWLEDGEMENTS

Some signals made it
back from the wild.

Selected acknowledgements from responsibly disclosed security research.

01

APPLE

Five web server security acknowledgements for responsibly disclosed vulnerabilities.

02

NASA

Acknowledged for identifying and responsibly reporting a security issue on a NASA domain.

03

TRIVAGO

Recognition for responsibly disclosing a security vulnerability.

04

HARMAN

Acknowledged for reporting a valid security issue through responsible disclosure.

05

DCU

Official acknowledgement from Dublin City University for identifying multiple security vulnerabilities.

06

FLYNAS

Acknowledged for responsibly reporting a security issue affecting the platform.

07

ZAIN

Recognition from the Zain mobile application for discovering and responsibly disclosing a vulnerability.

MODE

THE OPERATING PRINCIPLES

01 / CURIOSITY

Ask why twice.

The first answer explains the feature. The second often explains the vulnerability.

02 / EVIDENCE

Make it reproducible.

A clean attack path, negative controls, and useful evidence beat a dramatic claim every time.

03 / SHARE

Leave a trail.

Good notes compound. Write-ups, tools, and methodology turn one hunt into the next researcher's head start.