James Lee

Sr Staff Application Security Engineer

United States
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
James Lee is a seasoned application security engineer with 18 years of hands-on experience in exploit development, protocol and binary reverse engineering, and automation for offensive security. Currently a Sr. Staff AppSec engineer, he has a deep background building implants, persistence, and C2 for macOS and Linux at scale, and previously worked on ICS protocol security at Idaho National Laboratory. He is a long-time Metasploit core developer and contributor—having implemented critical payloads and a PHP meterpreter as well as a certutil stager—bringing rare expertise in turning proofs-of-concept into reliable, production-grade exploitation tooling. Skilled in Ruby, C, PHP and exploitation automation, he blends low-level engineering with practical defensive insight. Collected across consulting, open source and in-house red team roles, his work emphasizes reliable tooling and reproducible techniques rather than one-off proofs.
code18 years of coding experience
job17 years of employment as a software developer
bookBachelor’s Degree, Computer Science, minor in Psychology, Bachelor’s Degree, Computer Science, minor in Psychology at New Mexico Institute of Mining and Technology
languagesEnglish, Spanish
github-logo-circle

Github Skills (18)

filesystem10
back-end-development10
it-security10
net10
process-management10
command-injection10
file-operations10
networking10
security10
php10
socket10
exploit10
fileio10
tcp-socket10
metasploit10

Programming languages (5)

JavaCGherkinJavaScriptRuby

Github contributions (5)

github-logo-circle
rapid7/metasploit-framework

Mar 2008 - Dec 2020

Metasploit Framework
Role in this project:
userBack-end Developer & Security Engineer
Contributions:2896 commits, 58 PRs, 24 pushes in 12 years 11 months
Contributions summary:James contributed significantly to the Metasploit Framework, a penetration testing tool. They added support for a `certutil` command stager, a technique for executing payloads on Windows systems. Additionally, the user addressed an encoding issue, which improved the reliability of the exploit. This demonstrates a focus on expanding the framework's capabilities and improving its stability, particularly concerning exploitation techniques and security.
metasploit
rapid7/metasploit-payloads

Jun 2010 - Nov 2012

Unified repository for different Metasploit Framework payloads
Role in this project:
userBack-end Developer
Contributions:75 commits, 3 PRs, 8 comments in 2 years 6 months
Contributions summary:James primarily contributed to the development of a PHP-based meterpreter, a core component of the Metasploit framework for post-exploitation. Their work involved implementing various functionalities, including file system interaction (chdir, delete, ls), process management (execute, kill), and network socket handling. They addressed bugs, enhanced the tool's features, and adapted it to leverage operating system specific APIs.
metasploit
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial