carlos@cesaints: ~/security — zsh

Command: security

security/ · updated

Security

Where I am in the move into offensive security, with evidence per level and nothing inflated.

Where I am

I have four years in development, architecture and technical leadership, and the security I know how to apply comes from there: authentication, data isolation, concurrency, headers, business-logic review in the systems I built. In offensive security I’m still in training. I have no professional pentesting experience, no security certification and no CVE, and I won’t pretend otherwise.

The ladder below shows what exists at each level and where to check it. Empty levels stay visible on purpose.

How I study

  • Methodology before tools: OWASP WSTG for the web, PTES for the structure of the work and the report, NIST SP 800-115 as a process reference.
  • The report is the product: every exercise ends with organized evidence and the builder-side fix, which is where my development background helps.
  • Authorized targets only: a platform lab, a system of mine or a program with written authorization. The full rules are in rules.

Evidence ladder

  1. Level 0Fundamentals in progress

    Dated notes and platform progress

  2. Level 1Guided practice

    Writeups of retired content, with the builder-side fix

    Nothing yet.

  3. Level 2Own project

    A tool or lab with public code

    Nothing yet.

  4. Level 3External validation

    A certification with a verification link, a CTF scoreboard

    Nothing yet.

  5. Level 4Authorized real world

    A disclosure-program report, a CVE with a vendor advisory

    Nothing yet.

  6. Cross-cutting, from building

    Security applied to systems I built

Security cases

Contact