Offensive Security | Web Application Testing | Security Projects
I am a Cybersecurity enthusiast focused on Offensive Security, Web Application Security and Security Operations. But still interested in other disciplines and may explore them in future.
I enjoy breaking applications in controlled environments, identifying vulnerabilities, and understanding how attackers think and how things just work under the hood, so that organizations can defend themselves better.
My long-term goal is to grow into a Application Security Expert role while expanding my skills in web security, offensive Security and red team operations
- Web Application Penetration Testing
- Vulnerability Assessment
- Network Security
- Linux Administration
- SIEM Monitoring
- Threat Detection
- Networking Fundamentals
- Technical Troubleshooting
- Nmap
- Burp Suite
- Metasploit
- Wireshark
- Nessus
- SQLMap
- Wazuh
- Linux
- Git/GitHub
Actively testing web applications for OWASP Top 10 vulnerabilities using Burp Suite, manual testing techniques, and vulnerable lab environments. Focus areas include authentication flaws, session management issues, and access control weaknesses.
Deployed an OwnCloud environment in a virtual lab and conducted ARP spoofing attacks to intercept authentication traffic. Captured credentials with wireshark and demonstrated session hijacking risks. Also configured wazuh siem and Xdr across multiple endpoints for threat detection, created brute-force detection rules, investigated suspicious processes, and improved monitoring visibility through dashboards and log analysis.
Completed hands-on labs covering:
- Web exploitation
- Enumeration
- Privilege escalation
- Authentication attacks
- OWASP vulnerabilities
- Bug bounty workflows
Completed multiple machines focused on:
- Enumeration
- Web exploitation
- Privilege escalation
- Credential attacks
- Linux exploitation
- Post-exploitation techniques
Documented attack paths, privilege escalation vectors, and remediation insights to strengthen real-world penetration testing methodology.
- TCM Security – Practical Bug Bounty
- Offensive pentesting - TryHackMe
- CyberShujaa Security Analyst Certification
- CIPT Data Protection Certification
- Conducted vulnerability assessments
- Assisted with external penetration tests
- Performed SOC monitoring using FortSIEM
- Supported security awareness initiatives
- Hardware/software troubleshooting
- System maintenance
- Identified security issues within systems
- Advanced Web Application Security Testing
- Bug Bounty Hunting
- C# and Python programming for hackers
- Automation
Email 📧: mayekuignatius@gmail.com
🔗 LinkedIn: www.linkedin.com/in/ignatius-mayeku-938b36267/