RED TEAM ACTIVE
INITIALIZING RED TEAM OPS
[ LOADING KERNEL... ]
127.0.0.1 · CEO w0lfr00t · Red Team · Bug Bounty

B0dj0x

CEO w0lfr00t · Red Team Operator · Bug Bounty Hunter
>

Offensive security specialist. I break systems so they can be built stronger. Top 1% on TryHackMe. Hunting vulnerabilities across the web, one bug at a time.

Top 1%
TryHackMe
22+
Security Tools
1+
CVE Found
3+
Bounty Platforms
Scroll
B0
B0dj0x
Red Team Operator · Bug Bounty Hunter
Available for engagements
b0dj0x@proton.me
📍
127.0.0.1
🔒
ProtonMail encrypted
0
CVEs Found
0
Security Tools
0
Certifications
Top
THM Global Rank

Future Cybersecurity Expert

I am a passionate and ambitious cybersecurity professional specializing in penetration testing, offensive security, and CTF challenges. As CEO of w0lfr00t and w0lfr00tlabs, I lead security research and build platforms for the cybersecurity community.

With a strong background in mathematics (Baccalaureat) and current studies in Science and Technology at USDB university, I hold solid analytical and technical foundations. I have developed 22+ open-source security tools used by bug bounty hunters and pentesters worldwide.

Actively developing my skills through practical challenges, security labs, and platforms like TryHackMe and HackTheBox, I continuously improve my expertise in network exploitation, web application security, and system vulnerabilities — preparing to pursue Telecommunications engineering to deepen infrastructure knowledge.

In addition to cybersecurity, I am a full-stack web developer, capable of designing modern, scalable, and secure web solutions. My multidisciplinary skill set allows me to approach problems from both a developer and security analyst perspective.

Skills & Expertise

A comprehensive offensive toolkit built through hands-on practice, real-world engagements, and continuous learning.

Web Security
Web App Pentesting85%
SQL Injection80%
XSS / CSRF78%
Caido / Burp Suite75%
OWASP Top 10Bug BountyAPI Security
Network Security
Network Pentesting75%
Port Scanning85%
CCNA Networking70%
NmapWiresharkMITM
Cloud & DevSec
AWS Security65%
Microsoft Sentinel60%
AWSSIEMIAM
</>Py
Programming
Python80%
Bash / Shell85%
JavaScript / PHP75%
Go / C / C#55%
PythonBashGoC
Red Team & OSINT
Reconnaissance85%
Google Dorking90%
CTF Challenges75%
OSINTReconSocial Eng.
Tools & Stack
Caidon8nMySQL Oracle SQLGitHubAWS PowerShellLinuxMetasploit

Security Arsenal

Real tools built for real-world security work. Open source, battle-tested, built from the ground up.

Recon Tool
b0d0rk — Google Dorking Engine
Automated Google Dorking tool for Bug Bounty reconnaissance. Generates and executes targeted dork queries to surface exposed assets, login pages, config files, and vulnerable endpoints at scale.
BashGoogle DorkingOSINTRecon
Network Tool
b0dj0xscn — Python Port Scanner
High-performance Python port scanner with support for single and multi-IP scanning, custom port ranges, socket timeout tuning, and color-coded terminal output for rapid enumeration during penetration tests.
PythonSocket ProgrammingNetwork Sec
Domain Intel
b0g0x — Domain Vulnerability Scanner
Comprehensive domain and IP scanner designed for bug bounty recon. Quickly gathers basic information, scans for common vulnerabilities, and maps the attack surface of target domains with structured output.
BashWeb App SecRecon
Security Tool
Black Book — Cybersecurity Arsenal
Comprehensive cybersecurity reference and tool collection. A curated arsenal of security scripts, payloads, wordlists, and techniques for red team operations and penetration testing.
BashPythonRed TeamPentesting
Community
w0lfr00t.com — Cybersecurity Community
A cybersecurity community platform for knowledge sharing, threat intelligence, and collaborative security research. Connecting security professionals and enthusiasts worldwide.
CommunityThreat IntelSecurity Research
CTF Platform
w0lfr00tlabs — CTF Challenge Platform
Capture The Flag platform hosting cybersecurity challenges across web exploitation, cryptography, forensics, reverse engineering, and more. Test your skills against real-world scenarios.
CTFChallenge DesignPlatform
OSINT
SubPhisher — Subdomain Takeover Scanner
Fast automated subdomain takeover scanner with 40+ service fingerprints, live DNS checks, and CNAME dangling detection.
PythonDNSOSINT
Security
JWTkiller — JWT Cracker & Forger
JWT token cracker, forger, and sniffer. Decode, crack weak secrets, forge tokens, and sniff JWT traffic in real-time.
PythonJWTAuth
Vulnerability
SSRFceptor — Blind SSRF Detector
Blind SSRF vulnerability detector with webhook callback server and 30+ OOB payloads for out-of-band testing.
PythonSSRFOOB
API
GraphQLploit — GraphQL Introspection Exploiter
GraphQL introspection exploiter with schema dumping, query builder, and automated vulnerability detection.
PythonGraphQLAPI
Recon
SubEnum — Subdomain Enumeration
Subdomain enumeration tool with 20+ free sources including crt.sh, DNS brute-force, and passive reconnaissance.
PythonDNSRecon
CORS
CORSbomber — CORS Misconfiguration Scanner
CORS misconfiguration scanner with 40+ origin mutations and automated detection of insecure CORS policies.
PythonCORSWeb
WAF
WAFNuker — WAF Detection & Bypass
WAF detection tool identifying 16+ WAFs with 150+ bypass payloads for SQLi, XSS, and command injection.
PythonWAFBypass
Vulnerability
Log4jScan — Log4Shell Scanner
Log4Shell (CVE-2021-44228) scanner with 30 JNDI payloads, callback server, and mass scanning capabilities.
PythonLog4jCVE
API
APIThief — REST/GraphQL API Discovery
REST and GraphQL API parameter discovery with 21 auth bypass techniques and automated endpoint enumeration.
PythonAPIAuth Bypass
OSINT
FaceTracer — Reverse Image Search
Real reverse image search with Trace.moe, SauceNAO, IQDB APIs and 11 stable search links including Google Lens and TinEye.
PythonOSINTImage
Email
EmailPhantom — Email Recon
Email reconnaissance tool with validation, DNS analysis, Gravatar lookup, social profiles, and breach checking across 26+ OSINT sources.
PythonEmailOSINT
Username
UserReaper — Username Harvester
Username enumeration across 656 platforms with intelligent verification, false positive filtering, and trust scoring.
PythonUsernameOSINT
Domain
DomainGhost — Domain Recon
Full domain reconnaissance with WHOIS/RDAP, DNS enumeration, tech stack detection, subdomain brute-force, and 36 OSINT links.
PythonDomainRecon
Threat Intel
LeakHunter — Threat Actor Intelligence
Threat actor profiles (12 APT groups), breach monitoring, password breach checking via HIBP, and leak source aggregation.
PythonAPTBreach
Vehicle
CarIntel — Vehicle OSINT
Vehicle intelligence tool with VIN decoder (150+ WMI codes), license plate lookup (50 US states), recall check, and stolen vehicle check.
PythonVINOSINT
Crypto
CryptoTracker — Crypto Wallet OSINT
Cryptocurrency wallet analysis with multi-chain support, entity attribution (30+ entities), and OFAC sanctions checking.
PythonBlockchainOSINT
Breach
PasteSniffer — Paste Site Scraper
Dark web paste site scraper with 32 leak detection patterns, 16 paste site scrapers, and breach database API checks.
PythonPasteLeak
Dark Web
TorCrawler — Dark Web Crawler
Dark web crawler with 8 category classifiers (drugs, cards, data, weapons), recursive .onion crawling, and 3 search engines.
PythonTorCrawler
Breach
LeakMiner — Breach Aggregator
Paste site and breach aggregator with 20 paste sites, 10 breach databases, 17 leak patterns, and real-time keyword monitoring.
PythonBreachMonitor
Dark Web
ForumScraper — Forum Scraper
Dark web forum scraper with 10 known forums, user reputation scoring (0-100), and 8 content categories.
PythonForumReputation
Stress Test
DDOSB0DJ0X — Stress Testing Tool
HTTP stress testing tool with 5 attack modes, Slowloris, custom payloads, live stats panel, and authorization gate.
PythonHTTPStress

Bounty Hunter

Hunting vulnerabilities across the world's top bug bounty platforms. Responsible disclosure. Real impact.

CVE
1+
CVEs Discovered
3+
Active Platforms
Top 1%
THM Global Rank
CTF Challenges

Certifications & Training

Platform recognitions and certification paths actively pursued.

🛡️
Penetration Tester Path
TryHackMe
✓ Completed
🎓
eJPT (In Progress)
INE Security
● In Progress
☁️
AWS Security
AWS Educate
✓ Completed
🔵
CS50 Computer Science
Harvard University
✓ Completed
🌐
SC-200: Microsoft Sentinel
Microsoft Learn
✓ Completed
🔑
CCNA Networking
Cisco (Course)
✓ Completed

Professional Experience

Jan 2024 – Present
Web App Developer & Network Engineer
Yousoft · 127.0.0.1
  • Built full-stack web applications from design to deployment
  • Maintained and updated existing production web applications
  • Implemented security best practices across the development lifecycle
  • Monitored and troubleshot complex network infrastructure issues
  • Designed and deployed local networks for corporate clients
  • Performed manual penetration testing to identify vulnerabilities in web applications
  • Managed and enhanced cloud security posture on AWS
  • Provided detailed remediation recommendations to clients

Education Timeline

2025 – Present
Science & Technology (ST)
USDB University · 127.0.0.1
2025 – Present
Junior Penetration Tester Course
INE / eJPT · Online
2025
CS50 — Computer Science Fundamentals
Harvard University · Online
2024
Ethical Hacking
HackersArise · Online
2020 – 2022
Web Development Course
Maxcenter · 127.0.0.1
2020 – 2022
CompTIA A+ (Arabic) & CCNA
Online Courses

Key Achievements

🏆
Global Top 1% on TryHackMe
Ranked in the global Top 1% by solving advanced real-world cybersecurity challenges across multiple domains.
🐛
CVE-2025-0133 Discovery
Found a vulnerability in Microsoft's website related to CVE-2025-0133. Out of scope, but a significant first discovery.
🌐
First Web App Sale
Successfully sold first commercial web application to APC Ahmer El'Ain on 11/09/2024.
📡
Enterprise Network Deployment
Designed and deployed complete local network infrastructure for APC Sidi Ghilas corporate office in 12/2025.

Cyber Lab

Simulated network topology with live attack visualization. Watch the red team in action.

SOC Dashboard · Network Topology Monitor · LIVE
Network Nodes
Attack Log

Live Terminal

Try: whoami · skills · projects · bounties · nmap localhost · help

b0dj0x@kali:~$ — bash
═══════════════════════════════════════════
B0dj0x Terminal v2.0.0 — Red Team Edition
═══════════════════════════════════════════
Type 'help' to see available commands.
b0dj0x@kali:~$

Trainings & Courses

🌐
Web Development
  • HTML / CSS / JavaScript
  • PHP / Python
  • MySQL Database
☁️
AWS Educate — Security
  • Getting Started with Security on AWS
🛡️
TryHackMe Paths
  • Jr. Penetration Tester
  • Web Fundamentals
🔵
Microsoft Learn
  • SC-200: Configure Sentinel
  • Linux & Shell Scripting
  • Introduction to GitHub
💻
Sa7ee7 Training
  • Networking Fundamentals
  • ISC2 Security
  • Bug Bounty Hunting
  • Ethical Hacking
🔑
eJPT Training
  • Penetration Testing Methodology
  • Web Security Introduction
  • Cloud Security Fundamentals

Contact Me

Let's Work Together
Available for bug bounty collaborations, security assessments, freelance pentesting, and full-stack development projects.
Email
b0dj0x@proton.me
Telegram
📍
Location
127.0.0.1
PGP Public Key
Contact via b0dj0x@proton.me for encrypted communications. ProtonMail provides end-to-end encryption by default for ProtonMail-to-ProtonMail conversations.
Message received. I'll get back to you within 24 hours.