// 0x6a_v1.0
Logo

0x6a03448f4d

AppSecPentestingSecurity Automation
curl -L https://0x6a03448f4d.com/cvCopy
./whoami.sh

I know that I
know nothing.

I am a passionate cybersecurity student specializing in Application Security and Penetration Testing. With a proactive mindset, I thrive in collaborative environments and embrace continuous, lifelong learning.

My focus lies in breaking and securing systems, building robust automation tools in Python, and experimenting with how artificial intelligence can drastically enhance vulnerability discovery and exploitation workflows.

> Actively targeting: AppSec, Pentesting, Red Team, and AI-Security oriented roles.

6
YEARS LEARNING
TOP 1%
HTB ACADEMY
232
TARGETS COMPROMISED
01.

Experience

AI Penetration Testing Project

10/2025 — 06/2026
Devoteam|Lisbon, Portugal
  • Developing AI-driven penetration testing agents using Python and large language models (LLMs).
  • Automating reconnaissance, exploitation, and reporting processes for web applications.
  • Designing workflows with LangChain and LangGraph, focusing on state management and reliability in security testing environments.
  • Applying academic knowledge to solve practical cybersecurity challenges in a real company context.

Application Security Engineer Intern

06/2025 — 09/2025
Celfocus|Lisbon, Portugal
  • Supported integration of SSDLC principles to ensure security throughout the development lifecycle.
  • Worked with SAST tools and integrated security checks into CI/CD pipelines using GitHub Actions.
  • Developed a Python script for vulnerability triage, automating analysis and prioritization to reduce manual effort and improve accuracy.
  • Collaborated in Agile teams, enhancing communication, problem-solving, and security-driven workflows.
02.

Education

2023 — Present

Bachelors Degree Cybersecurity

Iscte Instituto Universitário de Lisboa

Developed skills in cybersecurity, including threat detection, risk assessment, secure networks, encryption, and ethical hacking.

2020 — 2023

High School, Science and Technologies

Escola Secundária Maria Amália Vaz de Carvalho

Final Grade 16/20. Strong foundation in Mathematics and Physics. Enhanced critical thinking and ethical reasoning.

03.

Certifications

  • [01]SOC Analyst (HackTheBox Job role Path)
  • [02]CTI Certification @ arcX
  • [03]Cyber Threat Intelligence 101 (arcX)
  • [04]Introduction to Cybersecurity (Cisco Networking Academy)
  • [05]EF SET English Certificate (C2 Proficient)
  • [06]IELTS Certificate (Band 8)
04.

Arsenal

Offensive / Application Security

Application SecurityPenetration TestingBurpSuiteOWASP ZAPVulnerability Management & TriageOWASP TOP 10 AppSecSecurity Testing

Blue Team / Defense

Blue Team / Red TeamThreat DetectionElastic/SplunkSIEMIDS/IPSMalware AnalysisDigital ForensicsNetwork Security

Development & Engineering

PythonHTML/CSS/JavaScriptSoftware DevelopmentCI/CDDevSecOpsGITSSDLCAgile MethodologyLinux/Windows

Emerging Technologies

AI SecurityCryptographySecurity AutomationLangChain & LangGraph
05.

Deployments

$ dig +short *.0x6a03448f4d.com // live subdomains, things I actually shippedfull deployments page →
LIVE
secplus.0x6a03448f4d.com

Security+ SY0-701 Study Portal

Local-first exam prep engine

A full CompTIA Security+ (SY0-701) training platform I built from scratch. Weighted exam-readiness scoring by official domain percentages, adaptive custom quizzes, performance-based question (PBQ) labs, exam simulations, spaced-repetition flashcards, and a gamified XP / achievement system to keep the grind honest.

970
PRACTICE Q
164
LESSONS
26
PBQ LABS
22
ACHIEVEMENTS
Next.jsReactTypeScriptTailwindLocal-firstNo Tracking
LIVE
vault.0x6a03448f4d.com

vault

Client-side security toolkit

A privacy-preserving password toolkit that runs entirely in the browser. Local strength analysis, CSPRNG passphrase and password generation, a Have I Been Pwned breach check via k-anonymity, plus base64/hex/JWT tooling — the password never leaves the device. No backend, no tracking, nonce-based CSP.

100%
CLIENT-SIDE
0
TRACKERS
HIBP
K-ANONYMITY
AES-256
WEBCRYPTO
Next.jsTypeScriptWebCryptoZero-depsNo Tracking
LIVE
pastebin.0x6a03448f4d.com

paste

Zero-knowledge pastebin

An encrypted pastebin where the server never sees the plaintext. Text is encrypted in the browser with AES-256-GCM; only ciphertext is stored and the key travels in the link fragment. Burn-after-read, auto-expiry, a creator deletion token, rate limiting, and a nonce-based CSP.

AES-256
GCM
0
PLAINTEXT SEEN
TTL
AUTO-EXPIRE
CSP
NONCE-BASED
Next.jsTypeScriptWebCryptoUpstash RedisZero-knowledge
LIVE
privesc.0x6a03448f4d.com

PrivEsc Matrix

GTFOBins + LOLBAS + WADComs, unified

An offline-first privilege-escalation workbench that unifies six sources (GTFOBins, LOLBAS, WADComs, GTFOArgs, HijackLibs, LOLDrivers) into one instant search, with a reverse-shell generator, MSFVenom builder, TTY-upgrade and pivoting cheatsheets, and an enumeration scanner: paste your find -perm -4000 or sudo -l output and it highlights which binaries are exploitable.

2.7K
TECHNIQUES
6
SOURCES
0
EXTERNAL CALLS
CSP
NONCE-BASED
Next.jsTypeScriptFuse.jsOffline-firstNo Tracking

awaiting deployment

*.0x6a03448f4d.com // provisioning next vhost...

06.

Field Notes

Security Writeups & Research

A collection of my thoughts, vulnerability research, and penetration testing walk-throughs documented in a secure, static environment.

./access_notes.sh