alex@alekslabs:~$ whoami
alexis ivan romero — offensive security · latam
alex@alekslabs:~$ cat role.txt
pentester in training · web / active directory / AI-LLM security · bug bounty
alex@alekslabs:~$ ./deploy.sh --goal
alekslabs
whoami — about
> profile.txt
Cybersecurity student (SNHU, B.S. in progress) & hands-on pentester. I break things on purpose — in authorized labs, bug bounty programs and CTFs — then write clean reports in English.
> status.log
CompTIA PT1 exam — Oct 2026 · roadmap: eJPT → PNPT → OSCP.
TryHackMe: 50+ rooms, Top 5% · active on bug bounty (web, auth flows, IDOR).
skills — arsenal
nmapgobuster/ffufburp/caido
sql injectionxssidor
ssrfauth bypassactive directory
linux privescpythonbash scripting
osintthreat intelai/llm security
labs — evidence
vulnversity (tryhackme)
Full chain: nmap recon → gobuster → upload filter bypass (.phtml) → reverse shell → SUID systemctl privesc to root.
read writeup →kenobi (tryhackme)
SMB share recon, ProFTPD mod_copy CVE-2015-3306, ssh key theft via NFS, PATH hijacking privesc. in progress
automation
aleksTools: subdomain enum, port scanner, dir scanner, header scanner, alive checker — open source.
github →threat intel monitor
Automated CISA KEV + NVD monitor — what's exploited today, delivered daily.