0x6a03448f4d
I know that I
know nothing.
I am a passionate cybersecurity student specializing in Application Security and Penetration Testing. With a proactive mindset, I thrive in collaborative environments and embrace continuous, lifelong learning.
My focus lies in breaking and securing systems, building robust automation tools in Python, and experimenting with how artificial intelligence can drastically enhance vulnerability discovery and exploitation workflows.
> Actively targeting: AppSec, Pentesting, Red Team, and AI-Security oriented roles.
Experience
AI Penetration Testing Project
10/2025 — 06/2026- Developing AI-driven penetration testing agents using Python and large language models (LLMs).
- Automating reconnaissance, exploitation, and reporting processes for web applications.
- Designing workflows with LangChain and LangGraph, focusing on state management and reliability in security testing environments.
- Applying academic knowledge to solve practical cybersecurity challenges in a real company context.
Application Security Engineer Intern
06/2025 — 09/2025- Supported integration of SSDLC principles to ensure security throughout the development lifecycle.
- Worked with SAST tools and integrated security checks into CI/CD pipelines using GitHub Actions.
- Developed a Python script for vulnerability triage, automating analysis and prioritization to reduce manual effort and improve accuracy.
- Collaborated in Agile teams, enhancing communication, problem-solving, and security-driven workflows.
Education
Bachelors Degree Cybersecurity
Iscte Instituto Universitário de Lisboa
Developed skills in cybersecurity, including threat detection, risk assessment, secure networks, encryption, and ethical hacking.
High School, Science and Technologies
Escola Secundária Maria Amália Vaz de Carvalho
Final Grade 16/20. Strong foundation in Mathematics and Physics. Enhanced critical thinking and ethical reasoning.
Certifications
- [01]SOC Analyst (HackTheBox Job role Path)
- [02]CTI Certification @ arcX
- [03]Cyber Threat Intelligence 101 (arcX)
- [04]Introduction to Cybersecurity (Cisco Networking Academy)
- [05]EF SET English Certificate (C2 Proficient)
- [06]IELTS Certificate (Band 8)
Arsenal
Offensive / Application Security
Blue Team / Defense
Development & Engineering
Emerging Technologies
Deployments
Security+ SY0-701 Study Portal
Local-first exam prep engine
A full CompTIA Security+ (SY0-701) training platform I built from scratch. Weighted exam-readiness scoring by official domain percentages, adaptive custom quizzes, performance-based question (PBQ) labs, exam simulations, spaced-repetition flashcards, and a gamified XP / achievement system to keep the grind honest.
vault
Client-side security toolkit
A privacy-preserving password toolkit that runs entirely in the browser. Local strength analysis, CSPRNG passphrase and password generation, a Have I Been Pwned breach check via k-anonymity, plus base64/hex/JWT tooling — the password never leaves the device. No backend, no tracking, nonce-based CSP.
paste
Zero-knowledge pastebin
An encrypted pastebin where the server never sees the plaintext. Text is encrypted in the browser with AES-256-GCM; only ciphertext is stored and the key travels in the link fragment. Burn-after-read, auto-expiry, a creator deletion token, rate limiting, and a nonce-based CSP.
PrivEsc Matrix
GTFOBins + LOLBAS + WADComs, unified
An offline-first privilege-escalation workbench that unifies six sources (GTFOBins, LOLBAS, WADComs, GTFOArgs, HijackLibs, LOLDrivers) into one instant search, with a reverse-shell generator, MSFVenom builder, TTY-upgrade and pivoting cheatsheets, and an enumeration scanner: paste your find -perm -4000 or sudo -l output and it highlights which binaries are exploitable.
awaiting deployment
*.0x6a03448f4d.com // provisioning next vhost...
Field Notes
Security Writeups & Research
A collection of my thoughts, vulnerability research, and penetration testing walk-throughs documented in a secure, static environment.
./access_notes.sh