Skip to content
View itzvenom's full-sized avatar

Block or report itzvenom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
itzvenom/README.md

Hi 👋, I'm Sérgio

Offensive Security Professional | Penetration Tester | CTF Player

  profile-views

👨‍💻 About Me

My name is Sérgio Charruadas aka itzv3nom- and I'm a cybersecurity professional with Web & API, Mobile (Android), Network and AD Exploitation as core focus, currently working as a Training Developer at Hack The Box. Transitioned from a decade-long career in hospitality into the cybersecurity field, bringing a strong customer-centric mindset and a unique perspective to technical problem-solving.

With hands of experience as an Offensive Security Operator/Penetration Tester, doing security consulting across multiple industries. My efforts directly supported enhancing clients’ security postures by identifying and providing recommendations regarding mitigations in various environments.

I hold several respected certifications from GIAC, HTB, OffSec, PortSwigger, and other industry-leading organizations. Actively contributed to the cybersecurity community by participating in - and speaking at - Hack The Box meetups in Portugal, helping foster local engagement and learning.


🧑‍💻 Platforms

Hack The Box badge

TryHackMe


🎯 Focus Areas

Area Skills & Tools
🔓 Web & API Pentesting Identifying OWASP Top 10 vulnerabilities, analyzing API logic flaws, performing authentication and authorization bypass tests
📱 Android Pentesting Assessing mobile app security, reviewing APKs for insecure storage, analyzing traffic with Burp Suite/Frida, testing for root/jailbreak detection bypass
🧱 Active Directory Security Assessments Performing comprehensive AD security reviews, evaluating privilege escalation paths, identifying misconfigurations, and assessing domain hardening effectiveness
🌐 Network Security Assessments Conducting network reconnaissance and vulnerability assessments, evaluating segmentation controls, identifying exposure risks, and validating remediation effectiveness
🧾 Reporting & Client Support Delivering clear, actionable reports that guide clients in strengthening their security posture, prioritizing risks, and implementing effective remediation strategies aligned with best practices

🎓 Certifications

Offensive Security

  • CPTS – Hack The Box, Certified Penetration Testing Specialist
  • CWES - Hack The Box, Certified Web Exploitation Specialist
  • ASCP – APISec University, API Security Certified Professional
  • CAPenX - SecOps Group, Certified AppSec Pentesting eXpert
  • OSCP - OffSec, Offsec Certified Professional

Defensive

  • BTL1 – Security Blue Team, Blue Team Level 1
  • SAL1 – TryHackMe, Security Analyst Level 1

Other Notable

  • GSEC – SANS GIAC, Security Essentials
  • GFACT – SANS GIAC, Foundational Cybersecurity
  • SY0-601 – CompTIA, Security+
  • CLF-C02 – AWS, AWS Cloud Practitioner
  • CRTA – CyberWarFare Labs, Certified Red Team Analyst
  • AD-RTS – CyberWarFare Labs, Active Directory Red Team Specialist
  • MCRTA – CyberWarFare Labs, Multi-Cloud Red Team Analyst
  • C-APIPen - SecOps Group, Certified API Pentester
  • CNPen – SecOps Group, Certified Network Pentester
  • CAPen – SecOps Group, Certified AppSec Pentester

🌍 Connect with Me

LinkedIn  

Pinned Loading

  1. Security-Assessment-PS Security-Assessment-PS Public

    PowerShell-based security assessment script by cube0x0 for Windows and Active Directory environments.

    PowerShell 12 1

  2. CVE-2023-6329 CVE-2023-6329 Public

    CVE-2023-6329 – Authentication bypass PoC for Control iD iDSecure ≤ 4.7.43.0

    Python 1

  3. Chewy-SecurityAWS Chewy-SecurityAWS Public

    Forked from birlzhimself/Chewy-SecurityAWS

  4. NET2GRID-Acquisition-Project NET2GRID-Acquisition-Project Public

    Forked from VascoLucas01/NET2GRID-Acquisition-Project

    PowerShell

  5. SimCorp-Project SimCorp-Project Public

    Forked from VascoLucas01/SimCorp-Project

    Python