Skip to content
View XoanOuteiro's full-sized avatar
🛠️
It's still magic even if you know how it's done.
🛠️
It's still magic even if you know how it's done.

Block or report XoanOuteiro

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
XoanOuteiro/README.md
Welcome Banner

Yo!

I'm an Ethical Hacker & Bug Bounty triager.
My pronouns are He/Him, and I'm currently learning reversing.

I work at Secur0, a Bug Bounty Startup, where I do somewhat of an offensive security lead role: webapp pentests on one side, triage for VDPs and Bug Bounty Programs on the other. We're also a CNA, so I've managed the disclosure of quite a bunch of CVEs, mostly on behalf of external researchers, which is why you'll usually see me tagged as analyst.

Outside of that I teach a fair bit, mostly hacking workshops at universities and vocational schools around Spain, and I build the odd CTF.

On the lamer side of things I'm also a CS student at Vigo University, Ourense Campus, mostly for fun.

I like helping people and communities with whatever they need, so if you've got a project or just want to chat, feel welcome to reach out. I'd rather work in open communities where people are not discriminated in any manner.

You can usually contact me on LinkedIn

I also host a cybersec blog


Mid Banner

🛠️ Tech & Tools that I Love ❤️

Programming Languages

Python   GoLang   Rust

IDEs and Editors

IntelliJ IDEA   Vim

OS and WM

Linux Mint   EndeavourOS   Arch Linux   Debian   Hyprland


Low Banner

🏆 Cybersecurity Certs & Badges

Google Cybersecurity Professional Certificate     eJPTv2 Certificate     eWPTX Certificate

Google Cybersecurity        eJPTv2        eWPTX

Bug Bounties & VDPs

Bugcrowd

Bugcrowd 5 Valid Bugs Badge    Bugcrowd Shogun Level 2 Badge

HackerOne

HackerOne Security Misconfiguration Badge    HackerOne Resolved an Issue Badge    HackerOne Good Samaritan Badge


End Banner

Pinned Loading

  1. attelier/egad attelier/egad Public

    Where a CNA triage team writes down the nuanced CVSS 4.0 calls. Arguably decent choices, argue back if you think you've got a better one.

    TypeScript 3

  2. tea tea Public

    A collection of Arch Dockerfiles to build specialized Recon, OSINT & Pentesting containers, simplified through the Teashop custom launcher.

    Rust 9 2

  3. caliper caliper Public

    Discover WAF bypass vectors for any payload on any HTTP method, the civilized way.

    Python 23

  4. rustybins rustybins Public

    A CLI GTFOBins browser

    Rust 3

  5. recon-toupa recon-toupa Public

    A swiss-knife tool for Bug Hunting & Web Pentesting reconaissance.

    Python 7 1

  6. attelier/ATT-CLI attelier/ATT-CLI Public

    An offline, CLI-based MITRE ATT&CK Matrix browser. Written in Rust.

    Rust 7