theoffsecgirl
offensive mindset · practical execution

theoffsecgirl

Pink lines. Red team.

I work the space between a weak technical signal and a defensible finding — research, applied methodology and the tooling that supports both.

Bug Bounty Research Tooling Teaching
current focus
auth boundary failures tenant isolation CORS classification path normalization weak-signal validation
ecosystem

Two surfaces. One methodology.

academy is where the methodology is taught. labs is where it's practised.

academylive
academy
academy.theoffsecgirl.com
Progressive bug bounty study program. 4 phases, 24 modules. From HTTP internals to specialized hunting. Not a course — a curriculum.
4 phases24 modulesEN / ES
academy.theoffsecgirl.com →
labscoming soon
labs
labs.theoffsecgirl.com
Practical lab environments for the academy modules. Hands-on exercises, vulnerable targets and guided hunting scenarios.
labsexercisesscenarios
in development
about
Offensive security with research, tooling and execution.
theoffsecgirl

Bug bounty, offensive research and cybersecurity education — with a bias toward execution over theory.

disclosed
CVE-2026-59237
built & maintained
5 open-source tools
teaching
Master's & FP level
more about how I work

Most of the day-to-day sits between the obvious finding and the report — triaging weak signals, validating ownership and authority, and turning a hunch into something a reviewer can act on. I also teach offensive security at master's and vocational training level — hacking ético, bastionado de redes y sistemas, and puesta en producción.

what I do

Built around signal, speed and validation.

Four threads. Same posture: practical, methodology-first, no theatre.

🎯

Bug Bounty

Attack-surface mapping, hypothesis-driven testing and validation focused on impact, not noise. Active on HackerOne.

🔬

Security Research

Turning weak technical signals into reproducible findings with clear security value. Methodology-first, always.

🛠

Tool Development

Building tooling that removes repetitive friction from recon, triage and validation work. Open source, on GitHub.

📐

Cybersecurity Education

Teaching offensive security through execution, workflow and applied reasoning. Master's and FP level.

teaching

Cybersecurity education through execution.

I teach offensive security at master's and vocational training level. Methodology-first, not slideware.

Hacking Ético

Web application security from first principles — HTTP semantics, same-origin, auth flows, triage methodology.

FP / Máster

Bastionado de Redes y Sistemas

Network and system hardening: attack surface reduction, configuration review, detection and response fundamentals.

FP / Máster

Puesta en Producción

Secure deployment, CI/CD security posture, infrastructure hardening and operational security for practitioners.

FP / Máster

Online Course (coming)

A structured offensive methodology course. Practical, execution-driven. Follow updates on academy.

Go to academy →
writing

Writeups and methodology notes.

Long-form offensive research writeups. Technical, methodology-first, no fluff.

Writeups are in progress — real cases, technical detail, no fluff.

Publishing via Substack. Subscribe to get notified when the first writeup drops.

Subscribe on Substack
contact

Professional contact and presence.

Open to collaborations, security training engagements, speaking and selected technical projects.

LinkedIn

Profile, background, training and networking.

@theoffsecgirl

Email

Direct contact for collaborations and proposals.

info@theoffsecgirl.com

GitHub

Open-source tools, utilities and technical projects.

github.com/theoffsecgirl