Colombian Ethical Hacker, Security Researcher and Software Engineer (aka DevCop95 / Dev101x) based in Cartagena, Colombia 🇨🇴. Ranked Top #18 GitHub Committers in Colombia, currently working as a Penetration Tester at Henkel (Switzerland · Remote) and pursuing a Master's in Artificial Intelligence at the Universitat de Barcelona.
My focus spans offensive security, vulnerability research (LOLBAS), and autonomous AI agent architectures — bridging low-level system exploitation and evasion techniques with automated intelligence pipelines.
- 🛡️ Vulnerability Researcher & LOLBAS Contributor: Authored Windows
Fsutil.exeexecution technique in the official LOLBAS Project (PR #525) (MITRE ATT&CK T1562.001); research cited in The Chinese University of Hong Kong (CUHK ITSC) security advisory. - 🎯 Offensive Security & Red Teaming: Active bug bounty hunter on HackerOne, developing automated recon/vulnerability frameworks (bugbounty-lab101), OSINT tools (shodan_reconsx), and credential extraction tooling (BDB-Guardian).
- 🇨🇴 Open Source Colombia: Ranked #18 active GitHub contributor in Colombia (committers.top/colombia).
- 🤖 Applied AI & Autonomous Agents: Engineering custom security skill layers and LLM integration pipelines (LangChain · Python · OpenAI · Claude).
- 🤝 Collaboration: Open to advanced Red Teaming, Applied AI Security, and technical consulting engagements.
Official contributor to the industry-standard LOLBAS Project, cataloging native Windows binaries leveraged for defense evasion and post-exploitation.
| Component | Detail |
|---|---|
| Binary & Technique | Fsutil.exe — Defense Evasion via 8dot3 Name Creation Tampering |
| Pull Request | LOLBAS-Project/LOLBAS #525 (Merged) |
| MITRE ATT&CK Matrix | T1562.001: Impair Defenses — Disable or Modify Tools |
| Academic / Advisory Citation | Cited by The Chinese University of Hong Kong (CUHK ITSC Security Advisory) |
| Research Impact | Demonstrates native OS execution paths to bypass file system telemetry and detection rules |
A complete bug bounty workspace for HackerOne researchers — scope enforcement, an automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists and a local VM practice lab. Built for disciplined, ethical hunting.
| Project | Stack | Description |
|---|---|---|
| 🛡️ LOLBAS-Project/LOLBAS | Official Contributor MITRE T1562.001 |
Official contribution: Fsutil.exe execution & defense evasion (PR #525 merged). Cited by Chinese University of Hong Kong (CUHK) |
| 🏹 bugbounty-lab101 | Shell Recon HackerOne |
Complete bug bounty workspace: 400+ tools, automated recon/vuln pipeline and scope enforcement |
| 🏦 BDB-Guardian | Python SecOps Forensics |
Banking credential scanner & memory dumper for incident response and red team simulation |
| 🔍 shodan_reconsx | Python Shodan Recon |
Shodan recon & OSINT intelligence gathering framework |
| 🕹️ pullgoscript | Go Windows C2 |
Lightweight C2 framework for Windows Red Team post-exploitation |
| 🤖 cyhber-deploy | Python Claude Gemini |
Security skill layer for Claude, Codex and Gemini AI agents |
| 🎓 cursos · live | JavaScript Supabase Tailwind |
Spanish-language course platform with a simulated browser terminal: Nmap on Windows (free) and Git & GitHub from scratch (premium) |
| 🧠 cYHBeriteratus | JavaScript LLM Local AI |
Private, filter-free local LLM interface for security engineers |
| Period | Role | Company |
|---|---|---|
| 2026 — present | 🛡️ Penetration Tester | Henkel · Switzerland (Remote · Part-time) |
| 2022 — 2025 | 🏢 Chief Technology Officer | EXIA S.A.S — Cartagena, CO |
| 2021 — 2024 | 💻 Semi-Senior Developer | |
| 2020 — present | 🚀 Freelance · Offensive Security & AI | Independent / Freelance |
| 2015 — 2016 | 📋 Administrative Assistant | CIER NORTE Project |
| Period | Degree | Institution |
|---|---|---|
| 2024 — present | 🤖 Master's in Artificial Intelligence | Universitat de Barcelona |
| 2017 — 2021 | 🎓 Systems & Computer Engineering | Universidad Tecnológica de Bolívar |
| 2013 — 2017 | 💡 Systems & Computer Technology | Universidad Tecnológica de Bolívar |
"Security is not a product, but a process. Code is poetry. Ship it."
⭐️ From DevCop95 · Colombian Ethical Hacker · Cartagena, Colombia 🇨🇴




