Cybersecurity (pentest, SOC) — Full-stack .NET developer
I combine building robust applications in ASP.NET Core / Blazor with a hands-on cybersecurity practice — audit, automation and exploitation.

A complete pass through the security cycle
- 01
Strategic audit
TCO analysis of in-house security governance and incident lessons-learned.
- 02
AI automation
Vulnerability management pipeline combining NVD, MITRE ATT&CK and a local LLM.
- 03
Exploitation
Reproducing and documenting a real CVE: RCE and privilege escalation.
- 04
Social engineering
Internal phishing simulation, measuring human risk and debriefing.
- 05
Infrastructure hardening
Active Directory audit against the ANSSI framework, GPO hardening and PowerShell-scripted remediation.
Cybersecurity work
Research dissertation
Proof-of-concept security dashboard and total-cost analysis of an in-house SOC vs. an outsourced one.
VulnAI
Automated vulnerability management pipeline combining NVD, MITRE ATT&CK and a local LLM.
CVE-2023-43208 — Mirth Connect
RCE and privilege escalation via an eval() injection on a HackTheBox machine.
Internal phishing simulation
Simulated phishing campaign at Génie Flexion: OSINT, sending, measurement and debrief.
Active Directory Audit & Hardening
Security audit of a Windows Server AD environment, scored against the ANSSI framework, remediated with PowerShell scripts (FGPP, GPO hardening).