Skip to content
View Pa7ch3s's full-sized avatar
馃惣
LockedIn
馃惣
LockedIn

Block or report Pa7ch3s

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don鈥檛 include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user鈥檚 behavior. Learn more about reporting abuse.

Report abuse
Pa7ch3s/README.md

pa7ch3s

10+ Years in this field and I still feel like a NOOB. Oh well, this is me!

Been in-house for the last 4 years. I heart: Red teaming, Pentesting (2 polar opposites btw); Security Research in general...

I'm also a habitual hand raiser for the test nobody wants: Thick Clients & NetPen.

Independent Security Consultant. I genuinely like being in the field!

My lane: thick clients. Everyone's off fuzzing web forms while the desktop app sits there with local admin, a signing cert, an auto-updater, and the structural integrity of a screen door. I got tired of testing those slowly, so I built the tooling that doesn't. Then I wrote down how, which is the repo below.

Also fluent in

  • Red team and adversary emulation. Physical/On-site, Social Engineering, Network, the whole walk from the parking lot to domain admin.
  • Web3 and smart-contracts (Oohhh yeaa... $$$).
  • Agentic AI, LLM, and agent security. = New toys, same old habit of trusting input they shouldn't. Just faster now.

Public work

  • Exploit Nation: Book 01, ThickClientAllTheThings, the desktop-app methodology I wanted on day one and had to write myself. Source.
  • More books, incoming.

Certs, for the box-checkers Zero Point Security CRTO 路 Certified Web3 Hacker 路 Blockchain Security Expert 路 CompTIA CySA+ 路 Cisco CyberOps Associate 路 INE Cloud Associate 路 AWS Cloud Foundations

Find me

Assessment and validation is authorized work only. Everything here is for defensive and educational use.

Popular repositories Loading

  1. lazyrecon lazyrecon Public

    Forked from nahamsec/lazyrecon

    This script is intended to automate your reconnaissance process in an organized fashion

    Shell 1

  2. www-project-thick-client-top-10 www-project-thick-client-top-10 Public

    Forked from OWASP/www-project-thick-client-top-10

    OWASP Foundation Web Respository

    Ruby

  3. Pa7ch3s Pa7ch3s Public

    Offensive security engineer and red team operator. Founder, Wickmark Group.

  4. exploitnation exploitnation Public

    Exploit Nation, Book 01: a field guide and testing methodology for desktop applications (Electron, Tauri, native, .NET, Java).

    HTML