Skip to content
View mac3d0's full-sized avatar

Block or report mac3d0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mac3d0/README.md

Rafael Macedo

Information Security Analyst  ·  Offensive Security & Penetration Testing  ·  Rio de Janeiro, Brazil

LinkedIn


Security analyst with 8+ years in penetration testing, ethical hacking and offensive security. Most of my work is hands on, breaking into web and mobile applications, testing corporate and cloud environments, and then sitting with the engineering teams to help close what I found.

I care about the part that comes after the exploit. A finding only matters when the developer reading the report can understand the risk, reproduce it, and ship the fix. That is where I spend the effort, on a clear proof of concept, honest severity, and remediation a team can actually act on.

Areas of focus

Red Team Web Pentest API Pentest Infrastructure & Network Android Pentest iOS Pentest DevSecOps Code Review

What I do

  • Penetration testing on web and mobile applications, corporate networks and cloud environments
  • Vulnerability research and exploitation, from first analysis to a working proof of concept
  • Secure architecture reviews and hands on support for development, DevOps and DevSecOps teams
  • Source code review focused on finding and fixing real vulnerabilities, not chasing linter noise
  • Malware analysis and reverse engineering
  • Reporting that talks to engineers, business and management without dropping the technical detail

Frameworks and methodology

OWASP MITRE ATT&CK NIST PTES

Toolbelt

Python C Bash Linux Kali Burp Suite Metasploit Nmap Wireshark Ghidra Docker AWS

Approach

  • I chase impact, not noise. Five findings that change how a system is secured beat fifty that nobody reads.
  • I test like an attacker and write like a defender, with a real proof of concept, honest severity, and a fix that fits the next sprint.
  • I work close to the engineers. The report lands better when it is built with the people who own the code, not thrown over the wall.
  • I translate the finding for the room it is in, raw technical detail for the dev team, risk and business impact for management and commercial. Same issue, two languages.
  • Everything I run stays inside an authorized scope. No exceptions.

Contact

Pinned Loading

  1. post-cases-IA post-cases-IA Public

    Estudos de caso sobre usar IA e LLMs em Red Team e testes de seguranca ofensiva.

    Python