Home/Skills
01 Capabilities
How I operate
Click any module to expand. Not what I know — how I apply it, what I look for, and the output I expect to see.
Offensive Security
Strong
▼
What I Can Do
- Passive + active subdomain enumeration
- HTTP probing, tech fingerprinting, banner grabbing
- Web app testing — SQLi, XSS, IDOR, SSRF, command injection
- Network pentesting and port scanning
- Malware creation, analysis, and EDR evasion
- OSINT profiling and social engineering recon
How I Think
Identify attack surface → enumerate subdomains and open ports → fingerprint services → probe for vulnerabilities → document with severity and remediation. Always ask: what would an attacker do with this?
Tools
NmapMetasploitBurp Suite
MsfvenomGobusterNikto
ShodantheHarvesterr3con
Sample Output
[+] Target: company.com | 8 subdomains
[+] dev.company.com → Apache 2.4.7 Ubuntu
[!] Port 22 open — OpenSSH_6.6.1p1 (outdated)
[!] No HTTPS on dev — credentials exposed
[+] dev.company.com → Apache 2.4.7 Ubuntu
[!] Port 22 open — OpenSSH_6.6.1p1 (outdated)
[!] No HTTPS on dev — credentials exposed
What I Look For
Forgotten dev subdomains → SSH versions revealing OS age → Headers leaking framework versions → Login forms without rate limiting → Default credentials on admin panels
Defensive Security
Active
▼
What I Can Do
- Windows event log parsing and threat hunting
- Endpoint detection with Velociraptor + Sysmon
- Malware analysis — static and dynamic
- Incident response — identify, contain, eradicate, recover
- GRC frameworks — risk identification and control mapping
- Blue team operations and detection rule writing
How I Think
What did the attacker touch? Where did they move? What did they leave behind? I follow the artifacts — event IDs, registry keys, prefetch files, network connections — to reconstruct the timeline.
Tools
VelociraptorSysmonVolatility
CyberChefWiresharkEVTX Parser
Detection Example
[!] Event 4625 x47 in 2min → Brute force
[!] Event 4688: cmd.exe → mimikatz.exe
[!] Event 4624 NTLM WORKSTATION → DC01
[+] Timeline reconstructed. IOCs extracted.
[!] Event 4688: cmd.exe → mimikatz.exe
[!] Event 4624 NTLM WORKSTATION → DC01
[+] Timeline reconstructed. IOCs extracted.
What I Look For
Suspicious outbound traffic → DNS tunneling · Multiple failed logins → brute force · Unusual parent-child process chains → credential dumping · NTLM auth workstation to DC → lateral movement
Programming & Automation
Active
▼
What I Can Do
- Build security tools from scratch in Python
- Bash scripting for Linux automation and enumeration
- PowerShell for Windows administration and log parsing
- n8n workflow automation for security pipelines
- Web development — HTML, CSS, JavaScript
- API integration — Shodan, VirusTotal, AbuseIPDB
How I Think
If I'm doing a task manually more than twice, I script it. Security without automation doesn't scale. Every tool I build solves a real problem I faced during testing or analysis.
Languages & Tools
PythonBashPowerShell
JavaScriptHTML/CSSn8n
ScapyBoto3Rich
Code Sample
# Banner grabbing — r3con portscan module
def grab_banner(ip, port, timeout=2):
s = socket.socket()
s.settimeout(timeout)
s.connect((ip, port))
banner = s.recv(1024).decode("utf-8", errors="ignore")
return banner.splitlines()[0][:200]
def grab_banner(ip, port, timeout=2):
s = socket.socket()
s.settimeout(timeout)
s.connect((ip, port))
banner = s.recv(1024).decode("utf-8", errors="ignore")
return banner.splitlines()[0][:200]
Systems & Infrastructure
Developing
▼
What I Can Do
- Linux administration — filesystem, permissions, processes, networking
- Windows + Active Directory — enumeration, privilege escalation
- AWS, Azure, GCP security — IAM, VPC, flaws.cloud labs
- Lab deployment — Kali, Windows VMs, Velociraptor server/client
- Network configuration — subnets, routing, firewall rules
How I Think
Every system has a trust model. My job is to find where that trust is assumed but not enforced — over-permissive IAM roles, default credentials, missing network segmentation, unpatched services.
Platforms & Tools
Kali LinuxWindows ServerAWS
AzureGCPActive Directory
VelociraptorSysmonVirtualBox
What I Look For
IAM wildcard permissions → public cloud storage → default VPC configs → security groups open to 0.0.0.0/0 → unencrypted data at rest → missing MFA on privileged accounts
02 Proficiency
Where the hours went
Self-assessed against real work — tools I've shipped with, not tools I've read about. Honest numbers.
01 Languages & Scripting
Python90%
Bash80%
PowerShell65%
JavaScript60%
HTML / CSS75%
02 Offensive Security
Recon & OSINT90%
Web App Testing80%
Network Pentesting75%
Malware & EDR Evasion65%
Wireless Auditing60%
03 Defensive & DFIR
Windows Event Logs85%
Endpoint Detection75%
Incident Response70%
Memory & Disk Forensics65%
Malware Analysis60%
04 Cloud & Systems
Linux85%
AWS (IAM, VPC, S3)70%
Active Directory70%
Azure50%
Docker / K8s45%
Skills are only real with evidence
Every module above maps to something shipped. Twelve projects, real output, real findings.