Salam! I'm Əliəsgər Fətullayev — also known as Orest — a student at the Chemistry–Biology Specialized Republican Lyceum in Azerbaijan and an aspiring penetration tester.
My focus is offensive security: web application exploitation, Active Directory attack paths, and Linux privilege escalation. I build my own tools because the fastest way to truly understand a system is to try to break it — then document it so the fix is undeniable.
I'm also the founder of Vision Voice Assist — AI-powered assistive glasses that give sight a voice. Building real products taught me how systems are made; security is where I learned how they fall apart. I want to spend my career on the second half.
- 🔭 Currently grinding toward eJPT → CPTS → OSCP
- 🧠 Learning: Active Directory attack chains, malware analysis, exploit development
- 🛠️ Building: my CYBER-ARSENAL of offensive-security tools
- 🌍 Based in Baku · aiming to study & work abroad
- 💬 Ask me about pentesting, Linux, or assistive AI
"hack the planet. then document it properly."
| Tool | Domain | What it does |
|---|---|---|
| 🦅 RAVEN | Recon / OSINT | DNS + subdomain enum, live-host probing, tech & WAF fingerprint, header audit → HTML |
| ⚒️ VULNFORGE | Vuln Research | Web tech/version fingerprint correlated to a known-CVE database + cookie/header audit |
| 👻 XSSPECTER | Web Exploitation | Reflected + DOM XSS scanner with payload mutation & headless-Chrome execution |
| 🔩 ROOTFORGE | Privilege Escalation | Dependency-free Linux privesc enumerator — SUID, sudo, caps, cron, GTFOBins |
| 🛡️ SENTINEL | Reporting | Bulk security-headers & clickjacking scanner that grades targets A–F (HTML + CSV) |
All under CYBER-ARSENAL · for authorized testing & education only.
Achieved ───────────────────────────────────────────────
Cisco Networking Academy ×2 (Cisco)
Roadmap ───────────────────────────────────────────────
eJPTv2 Junior Penetration Tester INE / eLearnSecurity [ in progress ]
CPTS Certified Penetration Tester HackTheBox Academy [ next ]
OSCP Offensive Security Certified OffSec [ final ]
I write about offensive security and the tools I build — clean, technical, no fluff.
- 📄 Catching DOM-Based XSS: The Bugs Your Proxy Scanner Misses
- 📄 Reconnaissance from First Principles: What I Learned Building RAVEN
More on Medium →