security researcher // kernel explorer
OFFENSIVE SECURITY RESEARCHER / CTF PLAYER & VULNEARABLE MACHINE BUILDER / CONFERENCE SPEAKER / DEFCON 34 SPEAKER
scroll to descend
Offensive Cybersecurity professional focused on offensive security, penetration testing, and red teaming, with hands-on experience identifying security weaknesses and supporting the development of more resilient systems.
Skilled in vulnerability research, security tooling, and improving organizational defenses through practical assessment and validation techniques.
Familiar with SOC environments, cloud security concepts, and threat intelligence analysis.
Driven by a strong interest in ethical hacking, modern attack techniques, and defensive cybersecurity practices through continuous learning and community contribution.
current
Novus // CLASSIFIED
Conduct web, internal, network, and cloud penetration testing to identify vulnerabilities, validate security controls, and uncover realistic attack paths. Perform manual and automated testing, exploitation, privilege escalation, and security assessments, delivering clear technical findings and actionable remediation guidance.
prior
Sentry // CLASSIFIED
Delivered web application penetration testing by identifying vulnerabilities such as authentication flaws, access control issues, and injection weaknesses, along with clear remediation guidance; performed mobile application security testing for Android and iOS using static and dynamic analysis to detect insecure data storage, API vulnerabilities, and misconfigurations; and conducted internal network penetration testing involving network enumeration, vulnerability exploitation, privilege escalation, and lateral movement to evaluate the organization’s internal security posture.
prior
Findbug // CLASSIFIED
Conducted penetration testing for media organizations and NGOs, identifying security vulnerabilities and helping strengthen their overall security posture. Authored detailed, high-quality security reports outlining discovered vulnerabilities along with clear and actionable mitigation strategies. These penetration testing engagements were funded by the U.S. Embassy as part of a grant awarded to the company.
origin
Starlabs // CLASSIFIED
Developed a Python-based dark web monitoring tool to detect leaked emails and improve breach awareness. Integrated OSINT techniques into security tools to enhance reconnaissance capabilities and support more effective intelligence gathering. Assisted in penetration testing projects with a focus on web application security and network hardening to strengthen overall system defenses.
Participated in a blue team CTF focused on securing an Active Directory environment, implementing defensive controls and monitoring to protect against live attacks from red team participants.
Competed in the European Union Agency for Cybersecurity's international CTF — one of the most prestigious security competitions in the European Cyber Security community.
Designed and operated multiple CTF competitions. Built infrastructure, wrote challenges across categories, and moderated competitive play for security communities.
Delivered talks at three conferences on offensive security and AI security topics: DEF CON 34 Demo Labs on weaponizing eBPF/XDP for covert triggered reverse shells, a session on prompt injection attacks and mitigation techniques, and another on deepfakes, focusing on their creation, real-world risks, detection methods, and broader societal impact.
Authored a detailed technical article on building a rootkit using the eBPF subsystem — covering hooking strategies, userspace/kernelspace communication, and detection evasion.
Co-organized DEF CON Prishtina (DC38338), a cybersecurity community event bringing together hackers and security researchers to share techniques, run hands-on “villages,” and collaborate on offensive security topics.
Authored a technical article on building an eBPF-based rootkit, covering techniques such as hiding its own PID, evading detection from tools like bpftool, spawning an encrypted reverse shell, and using XDP hooks triggered by a predefined “magic packet” for activation.
Read the article on Medium →
Source on GitLab (0xBabar0ka/Phantasma) →
Presented at DEF CON 34 Demo Labs, showcasing an eBPF/XDP-based implant framework enabling process hiding, BPF object cloaking, and covert network-triggered reverse shells activated via a predefined "magic packet." Walked attendees through the kernel-level persistence and evasion techniques and demonstrated the implant live.
Presented a conference talk on prompt injection attacks, explaining how attackers manipulate AI models by crafting deceptive inputs to bypass safeguards, disclose sensitive information, or alter responses. Covered the underlying mechanics of prompt injection, real-world applications, and best practices for mitigation. The session concluded with a live demonstration showcasing both attack techniques and defensive mechanisms in action.
Delivered a speaker session on deepfake technology, explaining how AI-generated images and videos are created and the processes behind their production, along with their increasing accessibility across both the surface web and dark web. Discussed detection methods, production costs of deepfakes, and broader political and social implications, including misinformation, identity theft, and election interference. The presentation also provided practical guidance on identifying deepfakes and reducing associated risks.
Iowa CTF
Overall Champion 2023
07 — contact
I don't respond to everyone. If you're building something interesting in the kernel or offensive security space, or want a speaker who actually knows what they're talking about — reach out.