Back to templates
Skip to main content
recon.sh
root@cipher:~$
Cybersecurity Student

Finding the exploit before the attacker does.

Junior Cybersecurity student specializing in offensive security — CTF competitor, SOC intern, and builder of tools that hunt vulnerabilities before they ship.

120+Boxes rooted
Top 2%HTB global rank
35+CTFs played
3Bugs disclosed
Leo Navarro, Cybersecurity Student
ACCESS GRANTED
🎯 Top 2% on HackTheBox
>_ Nmap>_ Wireshark>_ Burp Suite>_ Metasploit>_ John the Ripper>_ Ghidra>_ Splunk>_ BloodHound>_ Python>_ Linux>_ Nmap>_ Wireshark>_ Burp Suite>_ Metasploit>_ John the Ripper>_ Ghidra>_ Splunk>_ BloodHound>_ Python>_ Linux
01About

Trained to think like the attacker.

Focus areas

  • Web application security (OWASP Top 10)
  • Network penetration testing
  • Malware analysis & reverse engineering
  • Cloud misconfigurations (AWS / Azure)

I'm a junior Cybersecurity student who spends more time breaking systems than building them — on purpose. From campus CTFs to a SOC internship triaging real alerts, I'm chasing the moment a system reveals an assumption it shouldn't have made.

A vulnerability you can't explain isn't a finding yet. I default to reproducible proof-of-concepts, clear writeups, and remediation steps a developer can actually act on — not just a CVSS score.

Relevant coursework

Network Security & CryptographyOffensive Security & Penetration TestingDigital Forensics & Incident ResponseSecure Software Development
Westbrook State University·B.S. in Cybersecurity (Junior)
Austin, TX·Open to SOC & AppSec internships
02Operations Log

CTFs, pentests & bug bounty finds.

OP-01Critical

OPERATION NIGHTCRAWLER

Web App Pentest — University Capstone CTF

Led a 4-person red team against a simulated e-commerce platform, chaining an authentication bypass and stored XSS into full account takeover.

Burp SuiteSQLmapPython
  • Chained 3 SQLi-based auth bypasses into admin access
  • Escalated to root via a misconfigured sudoers entry
  • Delivered a 22-page report with a remediation timeline
OP-02High

OPERATION GLASSHOUSE

Internal Network Pentest — Security Club Range

Built and attacked a 12-host Active Directory lab to practice lateral movement and privilege escalation for the club's training pipeline.

NmapImpacketBloodHoundMimikatz
  • Compromised domain admin via Kerberoasting
  • Mapped the full attack path with BloodHound
  • Documented detections for the blue team to test against
OP-03Medium

OPERATION DRIFTWOOD

IoT Firmware Teardown

Extracted and reverse-engineered firmware from a consumer router, surfacing a hardcoded credential and an unauthenticated debug shell.

GhidraBinwalkQEMU
  • Found hardcoded root credentials in the firmware blob
  • Identified an unauthenticated debug shell on port 23
  • Disclosed responsibly to the vendor before publishing
OP-04High

OPERATION TIDELINE

Bug Bounty — Authentication Logic Flaw

Found a race condition in a SaaS password-reset flow that allowed account takeover by winning a timing window during token generation.

Burp SuiteTurbo IntruderPython
  • Reproduced the race condition with a 94% success rate
  • Disclosed via the program's responsible disclosure policy
  • Received a bounty and a public acknowledgment
03Field Log

Two years in the field.

Security Operations Center Intern · Meridian Financial

May 2025 — Aug 2025

Monitored SIEM alerts across a 400-endpoint network, triaged incidents, and helped tune detection rules to cut false positives.

SplunkIncident ResponseThreat Hunting

President, Cybersecurity Club · Westbrook State University

Sep 2024 — Present

Lead a 40-member club running weekly CTF practice and organized the campus's first 24-hour hacking competition.

LeadershipCTF CoachingEvent Ops

IT Help Desk Technician → Security Pivot · Westbrook University IT Services

Jan 2023 — May 2024

Started in tier-1 support, used the access to learn enterprise systems, then moved into auditing endpoint configurations for the security team.

Active DirectoryNetworkingEndpoint Hardening
04Arsenal

Tools & techniques, scanned.

// Offensive Security

Web Exploitation (OWASP Top 10)90%
Network Penetration Testing82%
Active Directory Attacks75%
Exploit Development58%

// Defensive Security

SIEM & Log Analysis (Splunk)78%
Incident Response70%
Threat Hunting65%
Digital Forensics60%

// Tools & Scripting

Python88%
Bash80%
Burp Suite / SQLmap85%
Metasploit / Nmap84%

// Systems & Networking

Linux Administration86%
TCP/IP & Routing80%
Docker & Virtualization72%
Cloud Security (AWS / Azure)55%
05Credentials

Certifications & clearances.

CompTIA Security+

CompTIA

2024

eJPT — Junior Penetration Tester

INE / eLearnSecurity

2024

CompTIA Network+

CompTIA

2023

OSCP — In Progress

Offensive Security

Target 2026

06Open A Channel

Got a target worth testing?

Internships, CTF teams, bug bounty tips, or a system you think can't be broken — open a channel and let's find out.

© 2026 Leo Navarro — connection secure