Systems online

CR3CKA SECURITY

Ethical Hacking Penetration Testing OSINT Digital Forensics Cloud Security AI Security

I break things on purpose so real attackers can't. A portfolio, tool library, and research hub built for defenders who read the source before they trust the CVE.

120+
Assessments
40+
Open-source tools
6
Years in field
cr3cka@sec:~
$whoami
cr3cka — offensive & defensive security
$cat mission.txt
Find the flaw before someone with worse intentions does.
$
Scroll
Capabilities

Disciplines I operate in

Every engagement pulls from a mix of these. None of them exist in isolation.

Ethical Hacking

Authorized offensive testing that mirrors real adversary tradecraft.

Network Security

Segmentation review, firewall audits, and traffic-pattern analysis.

Web Security

OWASP-aligned application testing from auth flows to business logic.

OSINT

Mapping public attack surface before an attacker does it for you.

Cloud Security

IAM review, misconfiguration hunts, and container/image scanning.

Digital Forensics

Memory and disk analysis that reconstructs what actually happened.

Reverse Engineering

Taking binaries apart to understand exactly what they do.

Malware Analysis

Static and dynamic triage of samples in an isolated, controlled lab.

About

Security work should hold up under pressure — not just in a demo.

CR3CKA Security started as a personal lab for breaking down how real intrusions happen, and grew into a full practice spanning offensive testing, defensive tooling, and research writing.

My mission is simple: give teams an honest, adversary-informed view of their exposure — and the tooling to keep closing gaps after the engagement ends. My vision is a security culture where defenders move as fast as attackers, because they understand the same techniques.

MissionFind real risk, explain it clearly, fix it fast.
VisionDefense that's proactive, not reactive.
Penetration Testing94%
OSINT & Recon90%
Cloud & Container Security85%
Digital Forensics80%
Journey
2019

First CTF, first rabbit hole

Started with capture-the-flag challenges and never really stopped.

2021

OSCP-style methodology

Formalized a testing methodology around real-world enterprise networks.

2023

Cloud & container focus

Shifted a large part of the practice toward cloud misconfig and IAM review.

2025

AI security research

Began researching prompt-injection and model-abuse defenses for LLM products.

Now

CR3CKA Security

Full-time practice: assessments, tooling, and public research writing.

Quick Reference

Tools & Commands

Searchable, filterable command references for authorized security assessments. Copy and go.

No tools match your search — try another keyword or category.
Open Source

GitHub Security Tools

A curated set of respected, actively maintained tools for legitimate security assessment, research, and defense.

Portfolio

Selected Projects

Tooling and research I've built and shipped publicly.

Live

Recon Pipeline

Automated subdomain-to-vuln pipeline chaining subfinder, httpx and nuclei.

GoBashDocker
Live

OSINT Correlator

Aggregates public data sources into a single graph of exposed assets.

PythonNeo4j
In Development

Cloud Config Auditor

Scans IaC templates for common cloud misconfigurations before deploy.

TypeScriptAWS
Live

Malware Triage Notebook

Jupyter-based static/dynamic triage workflow for sample analysis.

PythonYARA
Archived

CTF Writeup Archive

Two years of documented CTF solutions across web, pwn, and crypto.

Markdown
In Development

LLM Prompt-Injection Test Suite

A growing benchmark for probing AI product defenses against abuse.

PythonLLM APIs
Research

Latest Writing

Notes from the field — techniques, retrospectives, and defensive guidance.

Cloud Security

Five IAM misconfigurations I still find every engagement

The patterns that keep showing up across otherwise mature cloud environments.

Jun 18, 20266 min read
OSINT

Building a recon pipeline without losing signal in noise

How to chain subfinder, httpx and nuclei without drowning in false positives.

May 30, 20268 min read
AI Security

Prompt injection is just untrusted input, and we're relearning that

Old web-security lessons, new attack surface — what actually transfers.

May 12, 20267 min read
Learn

Learning Roadmap

The order I'd recommend if you're starting from zero.

🐧 Linux

  • Filesystem & permissions
  • Shell scripting
  • Process & service management
  • Package managers

🌐 Networking

  • TCP/IP fundamentals
  • DNS & routing
  • Packet analysis
  • Firewalls & VPNs

🐍 Python

  • Scripting fundamentals
  • Automation & APIs
  • Parsing & regex
  • Building simple tools

🔓 Web Security

  • OWASP Top 10
  • Auth & session flaws
  • Injection classes
  • Business-logic testing

📋 OWASP

  • Testing Guide
  • ASVS checklist
  • Cheat sheet series
  • Dependency-Check

🎯 Bug Bounty

  • Scope & rules of engagement
  • Recon methodology
  • Report writing
  • Triage & disclosure

🛡️ Blue Team

  • Log analysis
  • SIEM fundamentals
  • Incident response
  • Threat hunting

🗡️ Red Team

  • Attack-chain planning
  • Living-off-the-land
  • Evasion basics
  • Reporting & debrief
0
Projects Shipped
0
Tools Catalogued
0
GitHub Stars Referenced
0
Experience
Feedback

What clients say

"The report didn't just list findings — it explained exactly how an attacker would chain them. That context changed how we prioritized fixes."

RS
Rina S.
CTO, fintech startup

"Fast, thorough, and refreshingly clear communication throughout the engagement. Our cloud posture is measurably better."

DK
David K.
Head of Platform Eng.

"CR3CKA found a business-logic flaw two other vendors missed entirely. Worth every hour of the engagement."

AM
Amara M.
Security Lead, SaaS co.
Get in touch

Let's talk security

Open to assessments, consulting, and collaboration on defensive tooling.

LocationRemote — available worldwide