aleks@alekslabs: ~/portfolio
alex@alekslabs:~$ whoami
alexis ivan romero — offensive security · latam
alex@alekslabs:~$ cat role.txt
pentester in training · web / active directory / AI-LLM security · bug bounty
alex@alekslabs:~$ ./deploy.sh --goal

alekslabs

whoami — about

> profile.txt

Cybersecurity student (SNHU, B.S. in progress) & hands-on pentester. I break things on purpose — in authorized labs, bug bounty programs and CTFs — then write clean reports in English.

> status.log

CompTIA PT1 exam — Oct 2026 · roadmap: eJPT → PNPT → OSCP.
TryHackMe: 50+ rooms, Top 5% · active on bug bounty (web, auth flows, IDOR).

▮ drafting reports

skills — arsenal

nmapgobuster/ffufburp/caido sql injectionxssidor ssrfauth bypassactive directory linux privescpythonbash scripting osintthreat intelai/llm security

labs — evidence

vulnversity (tryhackme)

Full chain: nmap recon → gobuster → upload filter bypass (.phtml) → reverse shell → SUID systemctl privesc to root.

read writeup →

kenobi (tryhackme)

SMB share recon, ProFTPD mod_copy CVE-2015-3306, ssh key theft via NFS, PATH hijacking privesc. in progress

automation

aleksTools: subdomain enum, port scanner, dir scanner, header scanner, alive checker — open source.

github →

threat intel monitor

Automated CISA KEV + NVD monitor — what's exploited today, delivered daily.

contact — connect