Skip to content
View serafincpd's full-sized avatar

Block or report serafincpd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
serafincpd/README.md

👋 Hi, I'm serafincpd

Penetration Tester | Offensive Security · 🇦🇷


🔎 About

Engineering background spanning Development, SysAdmin, DevOps, and Cybersecurity before going full offensive. Builder first, breaker second — I maintain my own infrastructure, write custom tooling, and believe that understanding how things are built is what makes breaking them meaningful.


🎯 Offensive Security Focus

  • Wireless — 802.11 packet injection, rogue AP emulation, on-site wireless assessments
  • Web Application & Cloud — recon, subdomain takeover, cloud misconfiguration exploitation
  • Hardware & Embedded — ESP32 custom firmware, sub-GHz, RFID/NFC, BadUSB
  • Infrastructure Reconnaissance & OSINT

🚀 Technical Arsenal & Experience

  • Languages: Python - Bash - JavaScript - PHP
  • DevOps & Cloud: Docker - Kubernetes - AWS - Azure - GCP (attack surface, not just ops)
  • Offensive Tools: Burp Suite - Metasploit - Nmap - Wireshark - Nessus - Aircrack-ng
  • Expertise: Web App Pentesting, Active Directory Attacks, OSINT, Cloud & On-Prem

Hardware

├── Portable Hackbox    RPi + dual TP-Link WLAN (injection + AP emulation)
├── M5Stack Cardputer   ESP32 handheld with EvilCardputer Firmware
├── StickC Plus 2       Custom firmware: wrist-worn wireless toolkit [WIP]
└── FlipperZero         Sub-GHz · RFID/NFC · BadUSB

🛠️ Tools & Projects

StickC-HackerWatch [WIP]

Custom offensive firmware for M5Stack StickC Plus 2. WLAN deauth detection, network scanning, and attack capabilities from your wrist. Repo coming soon.

Self-hosted personal AI agent

Local AI assistant orchestrating knowledge management, finance tracking, and workflow automation via n8n. Built on Claude Code CLI with custom skills architecture.

mxchecksec (author)

Open source CLI for MX security auditing — SPF, DKIM, and DMARC validation. Blog Post


📫 Research & Writing

Blog (Spanish): www.serafincpd.com.ar

Medium (English): https://medium.com/@serafincpd

  • OSINT & infrastructure recon — Payoneer attack surface analysis
  • Cloud security — subdomain takeover via DNS misconfiguration
  • Container security & Linux internals — Docker privilege escalation

📜 Certifications

Certification Status
HTB CPTS — Certified Penetration Testing Specialist 🔄 In Progress
HTB CWES — Certified Web Exploitation Specialist 🔄 In Progress

💻 Training

HackTheBox — Hacker / Master I (Lvl 62) rank

Popular repositories Loading

  1. awesome-python awesome-python Public

    Forked from vinta/awesome-python

    A curated list of awesome Python frameworks, libraries and software

    Python

  2. digitalocean-api digitalocean-api Public

    Forked from kireal/digitalocean-api

    Python wrapper for Digital Ocean API v2

    Python

  3. serafincpd.github.io serafincpd.github.io Public

    HTML

  4. awesome-pentest awesome-pentest Public

    Forked from enaqx/awesome-pentest

    A collection of awesome penetration testing resources, tools and other shiny things

  5. Awesome-Hacking Awesome-Hacking Public

    Forked from Hack-with-Github/Awesome-Hacking

    A collection of various awesome lists for hackers, pentesters and security researchers

  6. invitacion-wan-sera invitacion-wan-sera Public

    HTML