Skip to content

Navigation Menu

Sign in
Sign up
@d4w0d
d4w0d
Follow
View d4w0d's full-sized avatar
🎯
Focusing

_BI6D4DDY_ d4w0d

🎯
Focusing

Block or report d4w0d

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
d4w0d /README.md

> cat about_me.txt

name: _BI6D4DDY_
role: Penetration Tester | Security Researcher | Offensive Security
focus: Web/Cloud Security, Active Directory Attack Chains, Mobile Security (iOS/Android)
side_quest: Python data engineering & report automation
currently: Building out a full mobile pentesting lab (Frida, Objection, MobSF)

matrix terminal gif


> ls -la ./expertise

🌐 Web / Cloud Security

  • GraphQL & REST API abuse (IDOR, auth bypass)
  • JWT attacks (algorithm confusion, cracking)
  • Azure cloud misconfig (SAS tokens, blob storage IDOR)
  • Recon: JS bundle analysis, endpoint enumeration
  • Exposed .git directory & secret hunting

🏒 Active Directory / Internal

  • Kerberoasting, AS-REP Roasting
  • Pass-the-Hash / Pass-the-Ticket / Golden-Silver Tickets
  • BloodHound-driven privilege escalation
  • Windows priv-esc: Juicy Potato, service abuse, persistence

πŸ“± Mobile Security

  • Android & iOS static + dynamic analysis
  • SSL pinning bypass with Frida / Objection
  • MobSF, drozer, jadx
  • OWASP MASVS-aligned assessments

🐍 Automation / Data Engineering

  • Python data pipelines (MongoDB β†’ Excel)
  • Secret-extraction & recon tooling
  • Report automation with openpyxl

> nmap -sV arsenal


> cat current_mission.log

[+] Enumerating attack surface...
[+] Fuzzing GraphQL / REST endpoints for IDOR...
[+] Cracking JWTs (alg confusion, weak secrets)...
[+] Kerberoasting hq.vanguard.bank AD lab...
[+] Bypassing SSL pinning on Pixel 7 / iPhone X...
[+] Chaining vulnerabilities into full compromise...
[+] Documenting findings...
[+] Repeat.

🎯 Currently working on

  • Active Directory attack-chain lab (hq.vanguard.bank) β€” Kerberoasting, BloodHound, priv-esc
  • Full mobile pentesting lab across iPhone X + Pixel 7
  • Bug bounty research on HackerOne & Bugcrowd (GraphQL IDOR, Azure cloud misconfig, JWT attacks)
  • Python-based recon & secret-extraction tooling

> tail -f github_stats.log


Swap d4w0d for your real GitHub handle to activate these live cards.


> curl -s connect.sh

matrix code gif

"There is no patch for human stupidity." β€” every pentest report ever

Popular repositories Loading

  1. arabic-laravel-docs arabic-laravel-docs Public

    Forked from Syrian-Open-Source/arabic-laravel-docs

    The Laravel documentation.

    1

  2. godot_2D godot_2D Public

    1

  3. fullstack-nextjs-app-template fullstack-nextjs-app-template Public

    Forked from xizon/fullstack-nextjs-app-template

    A full-stack sample web application based on Next.js that creates a simple whole-website architecture

    TypeScript 1

  4. ipatool ipatool Public

    Forked from majd/ipatool

    Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

    Go 1

  5. WebShell-Compressor-Obfuscator WebShell-Compressor-Obfuscator Public

    A powerful, professional-grade tool for compressing and obfuscating web shells and exploit code. Designed for security researchers, penetration testers, and red teams.

    Python 1

  6. Inspeckage Inspeckage Public

    Forked from ac-pm/Inspeckage

    Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

    Java 1

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /