Portfolio / Dossier
PicasoTheDealer
Cybersecurity Researcher / Systems Engineer / Software Developer / Digital Designer
Addis Ababa, Ethiopia — Open to Remote
> whoami
Sup, I am a security researchers and a software engineer, I love to break
things and just see how and to what level they function, I mostly focus on
Offensive security at low-level to check if I can get buffer overflow on the
and develop apps, websites, and API, but on my free time I try to make some
digital arts like 3D designs, posters and drawings.
Core Projects
Project KASCVE
Automated Security Auditing Ecosystem & Penetration Tester
KASCVE is an automated security audit software for websites that tests your website for known CVE'S
and Top 10 OWASP vulnerability with an addition of active penetration test such as SQL Injection and
some others. A platform made for both desktop and android.
KiOS
Secure Linux Architecture
Architected a highly optimized, Arch-based Linux distribution engineered from the kernel up to
drastically reduce attack surfaces while maintaining maximum developer velocity. Developed custom
Python and Bash automation frameworks to handle system localization, automated provisioning
pipelines, and granular cryptographic storage layouts.
Zero-Day Enumeration: Telegram Animation Engine
rlottie Media Engine Fuzzing Research
Independent remote research focused on stress-testing the rlottie media engine. Engineered an
automated fuzzing harness utilizing AFL++ to execute systematic crash analysis, successfully
isolating potential memory corruption vulnerabilities, input validation failures, and hidden
memory leaks within third-party messaging integrations.
The-Donut
Terminal-Based 3D Rendering Engine in C++
Creative systems project implementing a 3D donut animation rendered entirely in the terminal
using C++. Developed raw mathematical rendering algorithms and strict memory management
constraints without relying on external graphical or rendering libraries.
Active Directory Exploitation
HTB Environments — WingData & Complex Corporate Labs
Exploited and compromised complex corporate Windows network lab environments. Utilized Impacket,
Mimikatz, and Rubeus to execute advanced Kerberos authentication manipulation, AD Certificate
Services (AD CS) exploitation, and Pass-the-Ticket (PtT) / Pass-the-Hash (PtH) techniques
to harvest credentials and achieve absolute domain dominance.
Graphic & Poster Design Gallery
My Poster designs and 3D renders.
Professional Experience
LaloDev
Software Engineer
June 2025 — November 2025
Engineered and optimized backend software architectures within a formal Software Development
Life Cycle (SDLC). Automated critical production infrastructure using Python, enforcing secure
version control integrity and codebase hardening. Collaborated asynchronously with distributed
teams to defend application logic against injection flaws and maximize server throughput.