About

I am brigante. I work in offensive security: penetration testing, vulnerability research and vulnerability analysis. This is my personal blog, where I collect my research — CVEs, writeups and technical notes on what I study and break.

Focus areas

  • Web application penetration testing
  • Vulnerability research
  • Active Directory
  • .NET / ViewState deserialization
  • File upload & RCE
  • Responsible disclosure

Certifications

  • OffSec Certified Professional+ (OSCP+)OffSec · Issued May 2025 · expires May 2028 · Credential ID 142002583
  • OffSec Certified Professional (OSCP)OffSec · Issued May 2025 · Credential ID 142002589
  • Web Application Penetration Tester eXtreme (eWPTX)INE · Issued Apr 2025 · expires Apr 2028 · Credential ID 139843674
  • eCPPTv2INE Security · Issued Feb 2022
  • eJPTINE Security · Issued Nov 2021
  • Certified Ethical Hacking Associate (E|HA)EC-Council · Issued Jun 2021
  • Hack The Box Pro Lab: OffshoreHack The Box · Issued Apr 2020 · Credential ID HTBCERT-8885D67474

Responsible disclosure

The vulnerabilities described here are reported to the vendor before publication, and technical details are released only after a patch ships or the agreed disclosure window expires. Testing is carried out exclusively on systems I own or am explicitly authorised to assess.

Disclaimer

This content is for research and educational purposes. Using these techniques against systems without authorisation is illegal: how you use what you read here is your responsibility.