Personal portfolio of Daniel Valdés — cybersecurity technician. CTF writeups, security research, and infrastructure security.
Kronos is a stager it opens a port on the test system waiting for a connection
All-in-one terminal toolkit for bug bounty recon, subdomain enumeration, takeover detection, and vulnerability scanning. Zero external binaries.
📚 Kali Linux Complete Guide - 40+ pages of penetration testing content with bilingual support, dark/light theme, and interactive TOC. Perfect for cybersecurity enthusiasts!
A defanged Go script modeling payload encoding and JSON/HTTP delivery mechanics for educational research.
Self-hosted attack-surface recon platform for bug bounty — subdomains, ports, URLs, JS secret extraction, CVE scanning, takeover detection, diff-monitoring alerts, HTML reports. 100% local & free.
PhiStack · Laboratorio Termux — estructura tu terminal Android para desarrollo y ciberseguridad: catálogo curado de 41 herramientas (código vendorizado), presets de terminal e IDE, bilingüe ES/EN.
Scanner: OWASP LLM Top 10 2024 vulnerability scanner — prompt injection, RAG poisoning, model poisoning, excessive agency detection in Python
Scanner: Web3/DeFi smart contract vulnerability scanner — reentrancy, oracle manipulation, flash loans, governance attacks in Python
Scanner: AI agent security scanner — multi-agent hijacking, tool misuse, context poisoning, goal manipulation detection in Python
Scanner: Identity provider attack scanner — Okta MFA bypass, Entra ID token theft, OAuth device code phishing, SAML replay in Python
Scanner: Software supply chain security scanner — dependency confusion, typosquatting, malicious packages, CI/CD injection detection in Python
Scanner: Mobile/IoT security scanner — Android exported components, iOS URL schemes, BLE pairing, MQTT/CoAP exposure in Python
Tool: Zero Trust architecture assessment — ZTNA config, device posture, microsegmentation, continuous verification validation in Python
Toolkit: Kubernetes security toolkit — RBAC privilege escalation, container escape, admission controller bypass, ETCD exposure in Python
Scanner: OWASP API Top 10 2023 + GraphQL security scanner — BOLA, BFLA, SSRF, introspection leaks, depth DoS in Python
Detector: Ransomware behavior detection — encryption patterns, mass file ops, shadow copy deletion, backup targeting in Python
The offensive-security atlas that knows what comes next. ⭐ Star to back the project.
Hide and extract payloads in audio files or streams, with encryption support and multiple formats.
🔍 JavaScript intelligence engine — extracts secrets, endpoints, params & API maps from JS bundles