Exploits,
red team ops,
mobile security.
I'm f1cu — solo security researcher & red team operator. Penetration testing, exploit development, iOS jailbreak research, Android FRP bypass, CVE analysis, API security testing. Python 3.11+ stack, asyncio-first architecture.
Solo operator. Deep technical focus.
Security research and offensive operations at scale. No consultancy overhead — direct access to tools, knowledge, and custom exploitation frameworks.
Exploit development
CVE research, PoC creation, weaponization. Custom payloads, staging chains, evasion techniques. Python + C/shellcode integration.
Mobile security
iOS jailbreak era knowledge applied to modern runtime. Sandbox escapes, entitlement abuse, IPC fuzzing. Android FRP bypass, firmware analysis.
Red team automation
Jebie_w_denko framework. CVE exploits, JWT attacks, OAuth/OIDC vulnerabilities, WAF bypass. Modular, async-first Python tooling.
What I deliver.
Fixed-scope engagements. Working code, documented findings, and knowledge transfer. No reselling, no overhead — you work with me directly.
Red team operations
Full-scope adversary simulation. Recon, initial access, lateral movement, privilege escalation, exfiltration. MITRE ATT&CK mapped. Detection engineering handoff.
- Assumed-breach scenarios
- Multi-stage exploitation
- Post-exploitation tooling
Mobile security research
iOS & Android deep-dive. Reverse engineering, runtime hooking with Frida, jailbreak surface analysis, entitlement hardening, sandbox escape research.
- Static + dynamic analysis
- IPC audit & fuzzing
- Jailbreak PoC development
Exploit development & automation
Custom PoC creation, weaponized exploits, CI-integrated security tooling. Python 3.11+, asyncio architecture. Delivered as standalone modules — yours to maintain.
- CVE weaponization
- Custom payload chains
- Owned automation frameworks
Open source & frameworks.
Tools built for red team operations and security research. Production-ready, heavily tested.
Jebie_w_denko
Red team automation framework
Modular exploitation framework. CVE exploits, JWT attacks, OAuth/OIDC vulnerabilities, API security testing, WAF bypass modules. Plugin-based architecture with shared utilities.
Apple-kombajn
iOS security tooling GUI
PySide6 desktop application for iOS security research. Jailbreak automation, FRP bypass, filesystem access, runtime hooking workflows. Cyberpunk-themed Qt widgets.
bunq API security research
Independent adversarial testing
Research into AI-assisted API flows, prompt-injection behavior, and SEPA transaction logic. Sensitive reproduction details intentionally withheld.
CVE Research & writeups
Active exploitation research
Published PoC exploits, technical writeups, and vulnerability analysis. Focus on zero-day discovery, privilege escalation chains, and mobile platform vulnerabilities.
Tools & frameworks.
Production-battle-tested. Selected for reliability, not trends.
- Python 3.11+
- asyncio
- FastAPI
- httpx
- Frida
- Burp Suite Pro
- Cobalt Strike
- Sliver
- Custom payloads
- Shellcode
- Frida
- Ghidra
- Hopper
- class-dump
- iOS internals
- Docker
- AWS
- Terraform
- Git
- Linux hardening
Specialized knowledge.
Penetration Testing
- Web/API security
- Infrastructure assessment
- Wireless networks
Mobile Security
- iOS jailbreak research
- Android FRP bypass
- Runtime analysis
CVE & Exploit Development
- Zero-day research
- PoC weaponization
- Privilege escalation chains
Offensive Automation
- Framework development
- CI/CD pipeline security
- Detection evasion
Have a target?
Scope out the engagement. What's the objective, the stack, and the timeline? I'll provide a quote and contract within 24 hours.