dev101x@kali:~$ whoamiColombian Ethical Hacker, Security Researcher and Software Engineer (aka DevCop95 / Dev101x), based in Cartagena, Colombia 🇨🇴. Currently a Penetration Tester at Henkel (Switzerland · Remote), and pursuing a Master's in Artificial Intelligence at the Universitat de Barcelona.
Focus: offensive security, vulnerability research, and autonomous AI agent architectures — bridging low-level system exploitation with automated intelligence pipelines.
dev101x@kali:~$ cat focus.txt- 🛡️ Vulnerability Research: Authored the Windows
Fsutil.exedefense-evasion technique in the official LOLBAS Project (PR #525, merged) — MITRE ATT&CK T1562.001. - 🎯 Offensive Security: Bug bounty hunter on HackerOne; builds automated recon/vuln pipelines and OSINT tooling (see pinned projects below).
- 🤖 Applied AI: Security skill layers and LLM integration pipelines (LangChain · Python).
- 🤝 Open to Red Teaming, Applied AI Security, and technical consulting engagements.
⚠️ Authorized use only. Every offensive/security tool linked below is built for use in scoped engagements, CTFs, bug bounty programs and environments the operator owns or is authorized to test. None of it is intended for use against systems without explicit permission.
| Component | Detail |
|---|---|
| Binary & Technique | Fsutil.exe — Defense Evasion via 8dot3 Name Creation Tampering |
| Pull Request | LOLBAS-Project/LOLBAS #525 (Merged) |
| MITRE ATT&CK | T1562.001: Impair Defenses — Disable or Modify Tools |
| Project | Stack | Description |
|---|---|---|
| 🛡️ LOLBAS-Project/LOLBAS | Official Contributor · MITRE T1562.001 |
Native Windows binary technique for defense evasion (PR #525, merged) |
| 🏹 bugbounty-lab101 | Shell · Recon |
Bug bounty workspace: recon/vuln pipeline, report templates, scope enforcement |
| 🧪 dev101x-pentest-lab | Docker · Python |
Self-contained Pro Lab-style box: blind SQLi → pivot → SUID privesc, with live flag validation |
| 🏦 BDB-Guardian | PowerShell |
SecOps / forensics tooling for incident-response simulation |
| 🔍 shodan_reconsx | Python · Shodan |
OSINT recon framework built on the Shodan API |
| 🤖 cyhber-deploy | Python |
Security skill layer for AI coding agents |
| Period | Role | Company |
|---|---|---|
| 2026 — present | 🛡️ Penetration Tester | Henkel · Switzerland (Remote · Part-time) |
| 2022 — 2025 | 🏢 Chief Technology Officer | EXIA S.A.S — Cartagena, CO |
| 2021 — 2024 | 💻 Semi-Senior Developer | |
| 2020 — present | 🚀 Freelance · Offensive Security & AI | Independent |
| Period | Degree | Institution |
|---|---|---|
| 2024 — present | 🤖 Master's in Artificial Intelligence | Universitat de Barcelona |
| 2017 — 2021 | 🎓 Systems & Computer Engineering | Universidad Tecnológica de Bolívar |
| 2013 — 2017 | 💡 Systems & Computer Technology | Universidad Tecnológica de Bolívar |
"Security is not a product, but a process. Code is poetry. Ship it."
⭐️ From DevCop95 · Colombian Ethical Hacker · Cartagena, Colombia 🇨🇴
