Skip to content
View fxlpz's full-sized avatar
:shipit:
Studying...
:shipit:
Studying...
  • Aberto a oportunidades
  • πŸ“ SΓ£o Paulo, Brazil

Block or report fxlpz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
fxlpz/README.md

fxlpz

β”Œβ”€[fxlpz@sec]─[~]
└──╼ $ cat profile.txt

Overview

Offensive Security Specialist focused on vulnerability research and penetration testing. Passionate about breaking systems ethically to strengthen digital security posture.

Role: CTF Player | Red Team Jr | Pentest Jr
Age: 23
Mission: Finding and exploiting vulnerabilities before malicious actors do

Technical Expertise

Offensive Security

web_exploitation:
  - SQL Injection & NoSQL Injection
  - Cross-Site Scripting (XSS)
  - Server-Side Request Forgery (SSRF)
  - Local/Remote File Inclusion
  - Insecure Direct Object References

binary_exploitation:
  - Buffer Overflow Attacks
  - Return-Oriented Programming (ROP)
  - Format String Vulnerabilities
  - Reverse Engineering

network_penetration:
  - Port Scanning & Service Enumeration
  - Network Pivoting & Lateral Movement
  - Active Directory Exploitation
  - Wireless Security Assessment

post_exploitation:
  - Linux Privilege Escalation
  - Windows Privilege Escalation
  - Persistence Mechanisms
  - Data Exfiltration Techniques

Security Arsenal

Reconnaissance    β†’ nmap | masscan | gobuster | ffuf
Web Testing       β†’ Burp Suite Pro | OWASP ZAP | sqlmap
Exploitation      β†’ Metasploit | Empire | Cobalt Strike
Binary Analysis   β†’ Ghidra | IDA Pro | radare2 | gdb
Network Analysis  β†’ Wireshark | tcpdump | Responder
Post-Exploitation β†’ BloodHound | Mimikatz | PowerSploit

Development Stack

primary_languages = ["Python", "Bash", "C", "Go"]
scripting = ["JavaScript", "PowerShell", "Perl"]
specialization = "Security Tooling & Exploit Development"

def approach():
    return "Automate everything, document nothing sensitive"

Current Operations

β”Œβ”€[●] Active Engagements
β”‚
β”œβ”€[β†’] CTF Competitions
β”‚  └─ Participating in challenges across multiple platforms
β”‚     Focus: Web, Binary, Crypto, Forensics
β”‚
β”œβ”€[β†’] Bug Bounty Programs  
β”‚  └─ Hunting vulnerabilities in real-world applications
β”‚     Platforms: HackerOne, Bugcrowd, Intigriti
β”‚
β”œβ”€[β†’] Red Team Operations
β”‚  └─ Simulating advanced persistent threats
β”‚     Objective: Test detection and response capabilities
β”‚
└─[β†’] Continuous Research
   └─ Studying emerging attack vectors and defense mechanisms
      Focus: Zero-day research, CVE analysis

Methodology

[1] RECONNAISSANCE    β†’ Gather intelligence on target systems
[2] SCANNING          β†’ Identify open ports and services  
[3] ENUMERATION       β†’ Extract detailed system information
[4] EXPLOITATION      β†’ Gain unauthorized access
[5] POST-EXPLOITATION β†’ Maintain access and escalate privileges
[6] REPORTING         β†’ Document findings with remediation guidance

Philosophy

In the world of cybersecurity, the best defense comes from understanding the offense. Every vulnerability discovered is an opportunity to make systems stronger. Every exploit developed is a lesson in secure architecture.

Security is not about building impenetrable walls it's about understanding how walls can be breached and constantly reinforcing them.

Platforms

TryHackMe Badge
HackTheBox Badge

Professional Presence

β”Œβ”€[fxlpz@sec]─[~/connect]
└──╼ $ ls -la contacts/
  • LinkedIn:
  • Twitter/X:
  • Email:
  • HackTheBox:
  • TryHackMe:
  • Bug Bounty:

Certifications & Learning Path

[In Progress]
β”œβ”€ Desec Certified Penetration Tester (DCPT)
β”œβ”€ null
└─ ...

[Continuous Learning]
└─ Staying updated with latest CVEs, exploits, and security research

β”Œβ”€[fxlpz@sec]─[~]
└──╼ $ echo "Hack the planet. Secure the future." | sha256sum
3c7d8f9a2b1e5c4d6f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0  -

β”Œβ”€[fxlpz@sec]─[~]  
└──╼ $ exit

Profile Views

Pinned Loading

  1. python-ids-framework python-ids-framework Public

    Sistema de DetecΓ§Γ£o de IntrusΓ£o (IDS) baseado em regras, desenvolvido em Python com a biblioteca Scapy para anΓ‘lise de pacotes de rede.

    Python 1

  2. PyVigial PyVigial Public

    Um HIDS (Host-based Intrusion Detection System) simples, porΓ©m robusto e profissional, escrito em Python. O sistema monitora arquivos de log em tempo real, aplicando um conjunto de regras flexΓ­veis…

    Python

  3. ransomware-analysis-toolkit ransomware-analysis-toolkit Public

    Educational ransomware toolkit implementing RSA-4096 + AES-256-GCM encryption for cybersecurity research and malware analysis training. Multi-threaded Python implementation with PBKDF2 key derivation.

    Python

  4. RATao RATao Public

    RATΓ£o Γ© um projeto educacional em C#/.NET que demonstra uma arquitetura cliente-servidor para administraΓ§Γ£o remota (RAT).

    C#