Offensive Security Researcher | Systems Developer | Founder, Leviathan Offsec
Vulnerability Research · Firmware & Reverse Engineering · Attack Surface Management
> Vulnerability Research & PoC Development
> Embedded Systems & Firmware Analysis
> Attack Surface Intelligence & Delta Tracking
> High-Performance Security Tooling (Go + Python)
| Target | Severity | CWE | Details |
|---|---|---|---|
| decompress@4.2.1 | High | CWE-59 | Symlink escape & hardlink bypass (PoC) |
| Kimai 2.x | High | CWE-287 | Default APP_SECRET auth bypass (PoC) |
| Tianwen ERP | Critical | CWE-434 | Unauthenticated file upload (PoC) |
| braces@3.0.3 | Medium | CWE-400 | DoS via brace expansion (Analysis) |
Production security tools in Go and Python. See @leviathan-offsec.
Reconnaissance & Surface Analysis
- HostageLVX – High-speed dangling DNS & subdomain takeover engine. 30+ cloud provider CNAME verification.
- FenrirLVX – WordPress/CMS attack surface mapping with offline CVE correlation.
- surfacediff – Asset snapshot & perimeter delta diffing. Stdlib only, zero dependencies.
Languages
Go · Python (AsyncIO, FastAPI) · C/C++ · Bash · SQL
Reverse Engineering & Analysis
Ghidra · GDB · radare2 · binwalk · ARM32/ARM64/x86_64
Security Intelligence
CISA KEV · FIRST EPSS · Shodan API · DNS Protocol Analysis · Supply-Chain Auditing
Deep Experience
4+ years OSINT on cybercrime forums, IABs, 1-day exploit trade flows. Focus on operationalizing underground adversary intelligence into passive attack surface rules.
- Vulnerability research? Check the PoC links above or visit leviathan.ac
- Want to use our tools? Star the org repos; most are production-ready with zero external dependencies
- Have a lead? Email me at chinyeezy08@gmail.com