Skip to content
View cyeezy08's full-sized avatar

Organizations

@leviathan-offsec

Block or report cyeezy08

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cyeezy08/README.md

@cyeezy08

Offensive Security Researcher | Systems Developer | Founder, Leviathan Offsec

Vulnerability Research · Firmware & Reverse Engineering · Attack Surface Management

Website Organization Email


Focus Areas

> Vulnerability Research & PoC Development
> Embedded Systems & Firmware Analysis
> Attack Surface Intelligence & Delta Tracking
> High-Performance Security Tooling (Go + Python)

Public Research & CVE PoCs

Target Severity CWE Details
decompress@4.2.1 High CWE-59 Symlink escape & hardlink bypass (PoC)
Kimai 2.x High CWE-287 Default APP_SECRET auth bypass (PoC)
Tianwen ERP Critical CWE-434 Unauthenticated file upload (PoC)
braces@3.0.3 Medium CWE-400 DoS via brace expansion (Analysis)

Leviathan OffSec Tooling

Production security tools in Go and Python. See @leviathan-offsec.

Reconnaissance & Surface Analysis

  • HostageLVX – High-speed dangling DNS & subdomain takeover engine. 30+ cloud provider CNAME verification.
  • FenrirLVX – WordPress/CMS attack surface mapping with offline CVE correlation.
  • surfacediff – Asset snapshot & perimeter delta diffing. Stdlib only, zero dependencies.

Skills & Toolchain

Languages
Go · Python (AsyncIO, FastAPI) · C/C++ · Bash · SQL

Reverse Engineering & Analysis
Ghidra · GDB · radare2 · binwalk · ARM32/ARM64/x86_64

Security Intelligence
CISA KEV · FIRST EPSS · Shodan API · DNS Protocol Analysis · Supply-Chain Auditing

Deep Experience
4+ years OSINT on cybercrime forums, IABs, 1-day exploit trade flows. Focus on operationalizing underground adversary intelligence into passive attack surface rules.


Get Started

  • Vulnerability research? Check the PoC links above or visit leviathan.ac
  • Want to use our tools? Star the org repos; most are production-ready with zero external dependencies
  • Have a lead? Email me at chinyeezy08@gmail.com

Pinned Loading

  1. leviathan-offsec/HostageLVX leviathan-offsec/HostageLVX Public

    High-speed dangling DNS and subdomain takeover engine with native multi-cloud CNAME verification

    Go 1

  2. leviathan-offsec/FenrirLVX leviathan-offsec/FenrirLVX Public

    High-speed Go CLI for WordPress attack surface mapping, plugin fingerprinting, and offline CVE correlation

    Go 1

  3. WordPress_Exploit_Directory WordPress_Exploit_Directory Public

    CVE-2026-32475 — unauthenticated arbitrary file upload in Elementor Pro <= 4.2.1 (CVSS 9.0, CWE-434). PoC for authorised testing.

    Python 1