The story so far
Systems fail in interesting ways. This is how I got obsessed with finding out why — and what I'm building because of it.
Every system is built on assumptions, and security begins where those assumptions stop being true. Most of my best learning moments start with one question: what happens if this is used in a way it was never meant to be?
I'm Leo, some corners of the internet know me as r3tro_n3o. I didn't start with a mission, I started curious. I wanted to know how digital systems actually break, what happens when you push something past what it was built to handle. That curiosity turned into obsession fast, and the more I learned, the more I noticed how exposed things are around me. Scams, SIM-swaps, fraud — most people here have no idea how it works and even less recourse when it happens. Understanding the mechanics stopped being a hobby and started feeling necessary.
I started self-taught, working through Cybrary, OverTheWire, and TryHackMe with no real roadmap. Then came AfricaHackon's full curriculum: Linux, recon, Active Directory, wireless, web and API security, cloud, malware, DFIR, blue team. The whole stack, hands-on.
Right now I'm deep in CPTS prep, and cloud security is where I'm actually headed. AWS is where my real hands-on time lives (IAM, VPC, S3, EC2), and I'm building up Azure knowledge on top of that since it's more common in the environments I'll actually be working in. Offensive security is the muscle underneath all of it — you can't audit or defend what you don't know how to break.
The long game is NOX, a company built to make cybercrime harder, not easier. The short game is getting good enough that saying "I do security" stops being an aspiration and starts being just true.
What I actually believe
Three rules that survived every lab, every failed exploit, and every 3am log dive.
Break it yourself first
You don't know a system until you've tried to take it apart. I'd rather find the hole in a lab than read about it in a post-incident report.
Automate the boring part
Manual recon across five terminal windows teaches you nothing the second time. If I do a task twice, it becomes a script — that's where r3con and NetWatch came from.
Write down what you find
An undocumented finding is a rumour. Every project here ships with real output, real severity, and the actual fix — because that's what makes it useful to anyone else.
Tools & technologies
The stack I reach for daily — grouped the way I actually use them, not the way cert exams group them.
The story continues on the timeline
Certifications, labs, curriculum, and the roadmap that gets me from here to OSCP — and eventually to NOX.