Skip to content
View DevCop95's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report DevCop95

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DevCop95/README.md

Typing SVG

Portfolio Courses LOLBAS Contributor Rank Colombia GitHub LinkedIn HackerOne X Profile views


👋 About me

Colombian Ethical Hacker, Security Researcher and Software Engineer (aka DevCop95 / Dev101x) based in Cartagena, Colombia 🇨🇴. Ranked Top #18 GitHub Committers in Colombia, currently working as a Penetration Tester at Henkel (Switzerland · Remote) and pursuing a Master's in Artificial Intelligence at the Universitat de Barcelona.

My focus spans offensive security, vulnerability research (LOLBAS), and autonomous AI agent architectures — bridging low-level system exploitation and evasion techniques with automated intelligence pipelines.

  • 🛡️ Vulnerability Researcher & LOLBAS Contributor: Authored Windows Fsutil.exe execution technique in the official LOLBAS Project (PR #525) (MITRE ATT&CK T1562.001); research cited in The Chinese University of Hong Kong (CUHK ITSC) security advisory.
  • 🎯 Offensive Security & Red Teaming: Active bug bounty hunter on HackerOne, developing automated recon/vulnerability frameworks (bugbounty-lab101), OSINT tools (shodan_reconsx), and credential extraction tooling (BDB-Guardian).
  • 🇨🇴 Open Source Colombia: Ranked #18 active GitHub contributor in Colombia (committers.top/colombia).
  • 🤖 Applied AI & Autonomous Agents: Engineering custom security skill layers and LLM integration pipelines (LangChain · Python · OpenAI · Claude).
  • 🤝 Collaboration: Open to advanced Red Teaming, Applied AI Security, and technical consulting engagements.

🛡️ Vulnerability Research & Official Contributions

Official contributor to the industry-standard LOLBAS Project, cataloging native Windows binaries leveraged for defense evasion and post-exploitation.

Component Detail
Binary & Technique Fsutil.exe — Defense Evasion via 8dot3 Name Creation Tampering
Pull Request LOLBAS-Project/LOLBAS #525 (Merged)
MITRE ATT&CK Matrix T1562.001: Impair Defenses — Disable or Modify Tools
Academic / Advisory Citation Cited by The Chinese University of Hong Kong (CUHK ITSC Security Advisory)
Research Impact Demonstrates native OS execution paths to bypass file system telemetry and detection rules

⭐ Flagship project


Stars Forks

A complete bug bounty workspace for HackerOne researchers — scope enforcement, an automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists and a local VM practice lab. Built for disciplined, ethical hunting.


🛠️ Tech Stack

Languages

Python Go JavaScript TypeScript Dart PHP Bash

Security & Red Teaming

Kali Linux Burp Suite Metasploit Wireshark MITRE ATT&CK HackerOne

AI & Data Science

LangChain OpenAI Pandas NumPy scikit-learn

Frontend & Mobile

React Vue.js Flutter TailwindCSS

Backend & Cloud

Laravel Django Flask Node.js Docker Salesforce Linux


🚀 Featured Projects & Security Arsenal

shodan_reconsx bugbounty-lab101

Project Stack Description
🛡️ LOLBAS-Project/LOLBAS Official Contributor MITRE T1562.001 Official contribution: Fsutil.exe execution & defense evasion (PR #525 merged). Cited by Chinese University of Hong Kong (CUHK)
🏹 bugbounty-lab101 Shell Recon HackerOne Complete bug bounty workspace: 400+ tools, automated recon/vuln pipeline and scope enforcement
🏦 BDB-Guardian Python SecOps Forensics Banking credential scanner & memory dumper for incident response and red team simulation
🔍 shodan_reconsx Python Shodan Recon Shodan recon & OSINT intelligence gathering framework
🕹️ pullgoscript Go Windows C2 Lightweight C2 framework for Windows Red Team post-exploitation
🤖 cyhber-deploy Python Claude Gemini Security skill layer for Claude, Codex and Gemini AI agents
🎓 cursos · live JavaScript Supabase Tailwind Spanish-language course platform with a simulated browser terminal: Nmap on Windows (free) and Git & GitHub from scratch (premium)
🧠 cYHBeriteratus JavaScript LLM Local AI Private, filter-free local LLM interface for security engineers

💼 Experience

Period Role Company
2026 — present 🛡️ Penetration Tester Henkel · Switzerland (Remote · Part-time)
2022 — 2025 🏢 Chief Technology Officer EXIA S.A.S — Cartagena, CO
2021 — 2024 💻 Semi-Senior Developer Google
2020 — present 🚀 Freelance · Offensive Security & AI Independent / Freelance
2015 — 2016 📋 Administrative Assistant CIER NORTE Project

🎓 Education

Period Degree Institution
2024 — present 🤖 Master's in Artificial Intelligence Universitat de Barcelona
2017 — 2021 🎓 Systems & Computer Engineering Universidad Tecnológica de Bolívar
2013 — 2017 💡 Systems & Computer Technology Universidad Tecnológica de Bolívar

📊 GitHub Stats

 



GitHub activity summary for DevCop95

🌐 Connect

Portfolio Courses GitHub LinkedIn HackerOne X


"Security is not a product, but a process. Code is poetry. Ship it."


⭐️ From DevCop95 · Colombian Ethical Hacker · Cartagena, Colombia 🇨🇴

Pinned Loading

  1. bugbounty-lab101 bugbounty-lab101 Public

    A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab.…

    Shell 449 75

  2. cYHBer cYHBer Public

    La arquitectura de la evasión semántica

    20 1

  3. cyhber-deploy cyhber-deploy Public

    Security Skill ( Claude , Codex , Gemini )

    Python 19

  4. dev101_bot dev101_bot Public

    Bot telegram

    Python 18

  5. cYHBeriteratus cYHBeriteratus Public

    An uncensored local LLM interface built for security engineers. It enables private, filter-free interaction with abliterated models for vulnerability analysis and advanced scripting without cloud-b…

    JavaScript 19

  6. shodan_reconsx shodan_reconsx Public

    Portable passive hostname reconnaissance through Shodan CTL

    Python 38 2