Skip to content
View kahaf-commit's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report kahaf-commit

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kahaf-commit/README.md

Penetration tester who enjoys poking at networks and applications that were never meant to be broken.

Lately, I have been spending most of my time on internal and external network penetration testing, web application security, and API security — including privilege escalation chains, C2 infrastructure, and testing against the OWASP API Top 10.

Projects

Project What it does
Writeups-and-Walkthroughs Documents Active Directory exploitation, web application pentesting, and red team lab work using a recon-to-remediation methodology
Web-Application-Penetration-Testing Walkthrough repo covering PortSwigger Web Security Academy labs end-to-end, paired with real-world vulnerability breakdowns and bug bounty insights
API301 API security testing notes mapped to the OWASP API Top 10 — auth bypasses, BOLA, injection, and rate-limiting abuse
Scripts Utilities for reconnaissance, enumeration, and pentest workflow automation

Currently practicing on

TryHackMe · PortSwigger Web Security Academy · HackTheBox — building and breaking lab environments to stress-test what I learn.


📬 Let's Connect

Open to penetration testing, red team, Network Testing, and API security research conversations.

Message me on LinkedIn

Pinned Loading

  1. Writeups-and-Walkthroughs Writeups-and-Walkthroughs Public

    My Writeups and Walkthroughs

    Python

  2. API301 API301 Public

    Mastery of API Pentesting

  3. Scripts Scripts Public

    Cybersecurity scripts and utilities for reconnaissance, security testing, automation, and research - built with Python, Bash, and Windows tools.

    Shell 1

  4. Web-Application-Penetration-Testing Web-Application-Penetration-Testing Public

    A hands-on walkthrough repo for web application penetration testing (WAPT) — covering PortSwigger Web Security Academy labs end-to-end, alongside real-world vulnerability breakdowns and bug bounty …

    Python