Home About Projects Skills Journey Blog Contact
Building from Africa · Eyes on the global stage
Home/Skills
01 Capabilities

How I operate

Click any module to expand. Not what I know — how I apply it, what I look for, and the output I expect to see.

⚔
Offensive Security
Strong
▼
What I Can Do
  • Passive + active subdomain enumeration
  • HTTP probing, tech fingerprinting, banner grabbing
  • Web app testing — SQLi, XSS, IDOR, SSRF, command injection
  • Network pentesting and port scanning
  • Malware creation, analysis, and EDR evasion
  • OSINT profiling and social engineering recon
How I Think
Identify attack surface → enumerate subdomains and open ports → fingerprint services → probe for vulnerabilities → document with severity and remediation. Always ask: what would an attacker do with this?
Tools
NmapMetasploitBurp Suite MsfvenomGobusterNikto ShodantheHarvesterr3con
Sample Output
[+] Target: company.com | 8 subdomains
[+] dev.company.com → Apache 2.4.7 Ubuntu
[!] Port 22 open — OpenSSH_6.6.1p1 (outdated)
[!] No HTTPS on dev — credentials exposed
What I Look For
Forgotten dev subdomains → SSH versions revealing OS age → Headers leaking framework versions → Login forms without rate limiting → Default credentials on admin panels
🛡
Defensive Security
Active
▼
What I Can Do
  • Windows event log parsing and threat hunting
  • Endpoint detection with Velociraptor + Sysmon
  • Malware analysis — static and dynamic
  • Incident response — identify, contain, eradicate, recover
  • GRC frameworks — risk identification and control mapping
  • Blue team operations and detection rule writing
How I Think
What did the attacker touch? Where did they move? What did they leave behind? I follow the artifacts — event IDs, registry keys, prefetch files, network connections — to reconstruct the timeline.
Tools
VelociraptorSysmonVolatility CyberChefWiresharkEVTX Parser
Detection Example
[!] Event 4625 x47 in 2min → Brute force
[!] Event 4688: cmd.exe → mimikatz.exe
[!] Event 4624 NTLM WORKSTATION → DC01
[+] Timeline reconstructed. IOCs extracted.
What I Look For
Suspicious outbound traffic → DNS tunneling · Multiple failed logins → brute force · Unusual parent-child process chains → credential dumping · NTLM auth workstation to DC → lateral movement
⌨
Programming & Automation
Active
▼
What I Can Do
  • Build security tools from scratch in Python
  • Bash scripting for Linux automation and enumeration
  • PowerShell for Windows administration and log parsing
  • n8n workflow automation for security pipelines
  • Web development — HTML, CSS, JavaScript
  • API integration — Shodan, VirusTotal, AbuseIPDB
How I Think
If I'm doing a task manually more than twice, I script it. Security without automation doesn't scale. Every tool I build solves a real problem I faced during testing or analysis.
Languages & Tools
PythonBashPowerShell JavaScriptHTML/CSSn8n ScapyBoto3Rich
Code Sample
# Banner grabbing — r3con portscan module
def grab_banner(ip, port, timeout=2):
  s = socket.socket()
  s.settimeout(timeout)
  s.connect((ip, port))
  banner = s.recv(1024).decode("utf-8", errors="ignore")
  return banner.splitlines()[0][:200]
⚙
Systems & Infrastructure
Developing
▼
What I Can Do
  • Linux administration — filesystem, permissions, processes, networking
  • Windows + Active Directory — enumeration, privilege escalation
  • AWS, Azure, GCP security — IAM, VPC, flaws.cloud labs
  • Lab deployment — Kali, Windows VMs, Velociraptor server/client
  • Network configuration — subnets, routing, firewall rules
How I Think
Every system has a trust model. My job is to find where that trust is assumed but not enforced — over-permissive IAM roles, default credentials, missing network segmentation, unpatched services.
Platforms & Tools
Kali LinuxWindows ServerAWS AzureGCPActive Directory VelociraptorSysmonVirtualBox
What I Look For
IAM wildcard permissions → public cloud storage → default VPC configs → security groups open to 0.0.0.0/0 → unencrypted data at rest → missing MFA on privileged accounts
02 Proficiency

Where the hours went

Self-assessed against real work — tools I've shipped with, not tools I've read about. Honest numbers.

01 Languages & Scripting
Python90%
Bash80%
PowerShell65%
JavaScript60%
HTML / CSS75%
02 Offensive Security
Recon & OSINT90%
Web App Testing80%
Network Pentesting75%
Malware & EDR Evasion65%
Wireless Auditing60%
03 Defensive & DFIR
Windows Event Logs85%
Endpoint Detection75%
Incident Response70%
Memory & Disk Forensics65%
Malware Analysis60%
04 Cloud & Systems
Linux85%
AWS (IAM, VPC, S3)70%
Active Directory70%
Azure50%
Docker / K8s45%

Skills are only real with evidence

Every module above maps to something shipped. Twelve projects, real output, real findings.