theoffsecgirl
Pink lines. Red team.
I work the space between a weak technical signal and a defensible finding — research, applied methodology and the tooling that supports both.
Two surfaces. One methodology.
academy is where the methodology is taught. labs is where it's practised.
Bug bounty, offensive research and cybersecurity education — with a bias toward execution over theory.
more about how I work
Most of the day-to-day sits between the obvious finding and the report — triaging weak signals, validating ownership and authority, and turning a hunch into something a reviewer can act on. I also teach offensive security at master's and vocational training level — hacking ético, bastionado de redes y sistemas, and puesta en producción.
Built around signal, speed and validation.
Four threads. Same posture: practical, methodology-first, no theatre.
Bug Bounty
Attack-surface mapping, hypothesis-driven testing and validation focused on impact, not noise. Active on HackerOne.
Security Research
Turning weak technical signals into reproducible findings with clear security value. Methodology-first, always.
Tool Development
Building tooling that removes repetitive friction from recon, triage and validation work. Open source, on GitHub.
Cybersecurity Education
Teaching offensive security through execution, workflow and applied reasoning. Master's and FP level.
Vulnerabilities found and disclosed.
Public CVEs credited to independent research and responsible disclosure.
Tools organized by operational role.
Same projects, grouped by where they sit in a research workflow.
Web research helper for mapping attack surface and surfacing weak signals on inputs, headers and response shapes.
github → pathraiderPath-handling research tool. Studies how parsers, filters and middleware normalize candidate paths in a lab.
github → corskitCORS posture classifier. Reads a request/response pair and reasons about the policy without sending traffic.
github →Cybersecurity education through execution.
I teach offensive security at master's and vocational training level. Methodology-first, not slideware.
Hacking Ético
Web application security from first principles — HTTP semantics, same-origin, auth flows, triage methodology.
FP / MásterBastionado de Redes y Sistemas
Network and system hardening: attack surface reduction, configuration review, detection and response fundamentals.
FP / MásterPuesta en Producción
Secure deployment, CI/CD security posture, infrastructure hardening and operational security for practitioners.
FP / MásterOnline Course (coming)
A structured offensive methodology course. Practical, execution-driven. Follow updates on academy.
Go to academy →Writeups and methodology notes.
Long-form offensive research writeups. Technical, methodology-first, no fluff.
Writeups are in progress — real cases, technical detail, no fluff.
Publishing via Substack. Subscribe to get notified when the first writeup drops.
Professional contact and presence.
Open to collaborations, security training engagements, speaking and selected technical projects.