Cybersecurity Specialist and Red Team Engineer with over a decade of hands-on experience in IT infrastructure and offensive security. Focus on Red Team operations, Active Directory exploitation, Cloud Security (Azure/Entra ID), and advanced tool development for External Attack Surface Management (EASM).
$ whoami --profile
> Handle: Ls4ss
> Core Focus: Red Team, Active Directory Penetration Testing, Cloud Pentesting (Azure/Entra ID).
> Specialty: EASM Tooling, Exploit Development, OSINT & Threat Intel Automation.
> Handle Identity: H4x0r- Specialist in Computer Forensics and Information Security — IPOG (Research focused on OSINT integrity within legal and investigative frameworks).
- B.S. in Systems Analysis and Development — UNOPAR.
- Offensive Domain: Active Directory Exploitation, Cloud Identity Attacks (Entra ID), Application Pen Testing, Attack Surface Mapping.
- Security & Exploitation Tools: BloodHound, AzureHound, NetExec, Impacket, Responder, ROADtools, Certipy, Coercer, Hashcat, Burp Suite, Nuclei, Shodan, Censys, AlienVault OTX.
An asynchronous, modular, high-performance External Attack Surface Management (EASM) and Threat Intelligence engine designed for Red Teams and security researchers. It automates asset discovery, active verification, and vulnerability weaponization intelligence, transforming noisy telemetry into correlated, prioritized attack vectors.
- BloodHound-like Graph Modeling: Visualizes attack paths, target relationships, and exposed vectors using Cytoscape.js (
Target Root -> Domains -> IPs -> Services -> CVEs -> PoCs). - Recursive Discovery & CDN Bypass: Cascades TLS certificates, WHOIS, DNS resolution, and automated CDN proxy bypass (Cloudflare/Fastly/Akamai) to discover hidden infrastructure.
- Active Validation Pipeline: Integrates high-speed port scanning (Masscan) with WAF evasion and targeted vulnerability validation (Nuclei verified active rules).
- Risk Prioritization Matrix: Correlates CVSS Base Scores, FIRST EPSS probability, CISA KEV (Known Exploited Vulnerabilities), and public exploit repositories (ExploitDB, GitHub PoCs).
- Smart Non-Destructive Persistence: Built-in SQLite database engine with incremental merging (Smart Upsert) to track exposure history and asset provenance.
- CVE-2021-41773 / CVE-2021-42013: Apache HTTP Server 2.4.49/2.4.50 Path Traversal & RCE exploit.
- CVE-2020-29134: TOTVS Fluig Platform Path Traversal exploit.
- CVE-2020-13886: LFI exploit targeting Intelbras TIP VoIP devices.

