Skip to content
View Ls4ss's full-sized avatar
☠️
H4x0r
☠️
H4x0r

Block or report Ls4ss

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Ls4ss/README.md

Lucas Souza (Ls4ss)

Role Focus Handle

Cybersecurity Specialist and Red Team Engineer with over a decade of hands-on experience in IT infrastructure and offensive security. Focus on Red Team operations, Active Directory exploitation, Cloud Security (Azure/Entra ID), and advanced tool development for External Attack Surface Management (EASM).


$ whoami

$ whoami --profile
> Handle: Ls4ss
> Core Focus: Red Team, Active Directory Penetration Testing, Cloud Pentesting (Azure/Entra ID).
> Specialty: EASM Tooling, Exploit Development, OSINT & Threat Intel Automation.
> Handle Identity: H4x0r

Academic Background

  • Specialist in Computer Forensics and Information Security — IPOG (Research focused on OSINT integrity within legal and investigative frameworks).
  • B.S. in Systems Analysis and Development — UNOPAR.

Technical Skills & Toolset

Offensive Security & Methodologies

MITRE ATT&CK Active Directory Azure OWASP PTES STRIDE

  • Offensive Domain: Active Directory Exploitation, Cloud Identity Attacks (Entra ID), Application Pen Testing, Attack Surface Mapping.
  • Security & Exploitation Tools: BloodHound, AzureHound, NetExec, Impacket, Responder, ROADtools, Certipy, Coercer, Hashcat, Burp Suite, Nuclei, Shodan, Censys, AlienVault OTX.

Development & Infrastructure

Python Bash JavaScript TypeScript Linux Docker


Featured Projects & Research

EASM Engine Python Version FastAPI Cytoscape.js License

An asynchronous, modular, high-performance External Attack Surface Management (EASM) and Threat Intelligence engine designed for Red Teams and security researchers. It automates asset discovery, active verification, and vulnerability weaponization intelligence, transforming noisy telemetry into correlated, prioritized attack vectors.

  • BloodHound-like Graph Modeling: Visualizes attack paths, target relationships, and exposed vectors using Cytoscape.js (Target Root -> Domains -> IPs -> Services -> CVEs -> PoCs).
  • Recursive Discovery & CDN Bypass: Cascades TLS certificates, WHOIS, DNS resolution, and automated CDN proxy bypass (Cloudflare/Fastly/Akamai) to discover hidden infrastructure.
  • Active Validation Pipeline: Integrates high-speed port scanning (Masscan) with WAF evasion and targeted vulnerability validation (Nuclei verified active rules).
  • Risk Prioritization Matrix: Correlates CVSS Base Scores, FIRST EPSS probability, CISA KEV (Known Exploited Vulnerabilities), and public exploit repositories (ExploitDB, GitHub PoCs).
  • Smart Non-Destructive Persistence: Built-in SQLite database engine with incremental merging (Smart Upsert) to track exposure history and asset provenance.

Public Exploits & Security Research


Connect with me

LinkedIn Website GitHub

Pinned Loading

  1. ReconHound ReconHound Public

    Advanced Passive Recon Like a Boss

    Python 20 6

  2. CVE-2021-41773_CVE-2021-42013 CVE-2021-41773_CVE-2021-42013 Public

    Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

    Shell 20 7

  3. CVE-2020-29134 CVE-2020-29134 Public

    Exploit CVE-2020-29134 - TOTVS Fluig Platform - Path Traversal

    Shell 3 1

  4. azhound-dc azhound-dc Public

    Azurehound device code authentication

    Shell 1