STEADY

· · · · Pentester & Security-minded Engineer · · · ·
IBM 5100 Portable Computer
EL. PSY. KONGROO.
TryHackMe HackTheBox Python Shell Kali Linux BurpSuite Metasploit Nmap

I break into infrastructure (ethically) and audit it, bringing an offensive mindset to every system I touch. Security isn't a checkbox for me, it's how I think.

About Me

Pentester & Security-minded Engineer — working from home

Offensive Security

What I Break

Web app pentesting is my bread and butter, run against the OWASP Top 10 and mapped through MITRE ATT&CK. Every target gets a full vulnerability assessment before anything gets touched — scope first, always.

Recon & Enumeration

How I Map

nmap with NSE scripting is my first stop, backed up by Amass, Nikto, and DNSenum for full surface mapping. Once the attack surface is known, ffuf and gobuster do the heavy lifting on directory and vhost enumeration.

Web App Testing

What I Attack

BurpSuite is in my hands for Proxy, Repeater, and Intruder work, with OWASP ZAP as a second set of eyes. SQLMap automates the injection side so I can focus on the logic flaws that scanners miss.

Security Auditing

How I Harden

Log analysis, Linux hardening, and security configuration review turn findings into fixes. I close what I opened, so every engagement leaves the target stronger than I found it.

Tech Stack & Tools

What I know and what I'm learning

Before this — started coding with Java (CRUD apps, JWT auth, WEB clones) at Odysseus64, then moved into pentesting.

Core Skills

Hands-on experience

Offensive Security
Web App Pentesting, OWASP Top 10, MITRE ATT&CK, Vulnerability Scanning & Assessment
Recon & Enumeration
nmap (NSE scripting), Amass, Nikto, DNSenum, ffuf, gobuster
Web App Testing
BurpSuite (Proxy, Repeater, Intruder), OWASP ZAP, SQLMap
Exploitation
Metasploit Framework, Hydra
Reverse Engineering
Ghidra, IDA, radare2, APK decompilation/repackaging
Network Analysis
Wireshark, tcpdump
Password/Hash Attacks
John the Ripper, Hashcat
Security Auditing
Log Analysis, Linux Hardening, Security Configuration Review
Operating Systems
Debian, Ubuntu Server, Fedora Workstation, Kali Linux
Automation & Scripting
Bash, Python

Learning / Basic Level

Currently growing

Frontend Development
JS basics
Virtualization
Proxmox VE (HA, ZFS, PBS), KVM, LXC
Cloud
AWS, Azure
Automation
Ansible, CI/CD
Languages
Rust, Go
Storage & Networking
ZFS Storage Pools, VLANs, Linux Bridging
Databases
Redis

Projects

Offensive security, labs & tooling
Web App Pentesting
Recon & Enumeration
Exploitation
Security Auditing
Network Analysis
webdaw
Password & Hash Attacks
Reverse Engineering