Home About Projects Skills Journey Blog Contact
Building from Africa · Eyes on the global stage
// Offensive security in progress

Leo
Mugambi aka r3tro_n3o

I don't trust a system until I've tried to break it myself. So I build the tools to do that, then see what's left standing.

$ identify --role Cybersecurity Practitioner Penetration Tester Threat Hunter Security Researcher DFIR Practitioner Cloud Security CTF Player Ethical Hacker
// 12 projects shipped // 5 certifications // CPTS in progress
r3tro_n3o — zsh
┌──(r3tro_n3o㉿kali)-[~]
└─$
01 Live Ops Status

Current loadout

What's running on my machine and in my head right now. Updated as things change.

System status — online
[STUDYING]CPTS — HackTheBox Certified Penetration Testing SpecialistActive
[TOOLS]Nmap · Metasploit · Burp Suite · Wireshark · Msfvenom · Velociraptor · Sysmon
[LAB]Velociraptor + Sysmon DFIR Lab — Kali server / Windows 10 clientRunning
[FOCUS]Offensive Security · Threat Hunting · Red Team Ops · Malware Analysis
[CERTS]Google Cybersecurity · AfricaHackon · ALX Africa Professional Foundations
[ROADMAP]Security+ → eJPT → CPTS → OSCPIn Progress
[LOCATION]Building from Africa. Eyes on the global stage.
02 Selected Work

Tools built to break things

Three of twelve. Recon automation, network detection, and cloud misconfiguration scanning — each one solved a problem I actually hit.

CompletePython · CLI

r3con — OSINT Recon Tool

Multi-phase recon pipeline: passive subdomain enumeration, HTTP probing, rule-based tech fingerprinting, banner grabbing, Shodan enrichment, dual JSON+TXT reports with risk flags.

PythonShodan APIdnspythonRich
CompletePython · Scapy

NetWatch — Network IDS

Real-time network intrusion detection built on Scapy. Detects ARP spoofing, port scans, SYN floods, and DNS anomalies. Flags MITM attempts and reconstructs TCP streams.

PythonScapyTCP/IPIDS
CompletePython · AWS

AWScan — AWS Misconfig Scanner

Automated detection of IAM privilege escalation paths, public S3 buckets, open security groups, missing CloudTrail logging, and VPC misconfigurations.

PythonBoto3AWSIAM
03 Capabilities

How I operate

Not what I know — how I apply it. Four modes, one habit: enumerate first, document everything.

01 — STRONG

Offensive Security

Subdomain enumeration, web app testing, network pentesting, malware analysis and EDR evasion. I ask one question: what would an attacker do with this?

02 — ACTIVE

Defensive Security

Windows event log hunting, endpoint detection with Velociraptor + Sysmon, malware analysis, incident response. I follow the artifacts to rebuild the timeline.

03 — ACTIVE

Programming & Automation

Python security tools from scratch, Bash and PowerShell automation, n8n pipelines, API integrations. If I do it manually twice, I script it.

04 — DEVELOPING

Systems & Cloud

Linux and Active Directory internals, AWS/Azure/GCP security, lab deployment. Every system has a trust model — I find where it's assumed but not enforced.

Got something worth breaking?

Open to internships, freelance security work, bug bounty teams, CTF collabs, and anyone building something interesting in the security space.