Pentester | Web Dev | AI Dev
Breaking things securely, building them better.
I'm CyberA1eX — an aspiring penetration tester, web developer, and AI developer with a passion for understanding how systems break, and how to build them so they don't.
Currently working towards OSCP while building full-stack web applications, security tools, and AI-integrated projects. My work sits at the intersection of offensive security, software engineering, and automation.
Top 1% globally on TryHackMe — ranked against tens of thousands of active practitioners. I don't just read about attack techniques — I build the environments, run the attacks, and write the reports.
Verified certifications and achievements — view all on Credly →
Python-based scanner that automatically detects XSS and SQL injection vulnerabilities in web applications. Generates structured reports with severity ratings and remediation guidance.
Full-stack web application built with OWASP Top 10 compliance from the ground up. Demonstrates secure authentication, input validation, output encoding, and access control best practices.
Rule-based chatbot widget for website integration. Zero APIs, zero dependencies — one script tag embed. Covers services, projects, skills, and contact questions with keyword-matched responses.
Modular Python toolkit for automating common pentesting tasks: port scanning, subdomain enumeration, and log parsing. Designed for efficiency during recon and initial enumeration phases.
Browser-based secure file encryption tool using AES-GCM. Encrypts files client-side with auto-expiring download links and a split-key system — zero single-point-of-compromise sharing.
Bash script that automates Linux privilege escalation reconnaissance. Collects sudo rules, SUID/SGID binaries, cron jobs, network listeners, and sensitive files into a timestamped folder.
A curated collection of web development projects with screenshots, live demos, tech stack breakdowns, and code quality notes. Documents the journey from concept to deployed product.
A preview of what gets built — from login flows to security dashboards.
OWASP-aligned authentication — bcrypt, session management, CSRF protection, rate limiting.
Scan results dashboard — severity-rated findings with CVSS scores and remediation notes.
Drop-in chatbot — zero dependencies, one script tag, live on this portfolio.
Interested in working together or have a security question? Reach out.