Portfolio / Dossier

PicasoTheDealer

Cybersecurity Researcher / Systems Engineer / Software Developer / Digital Designer
Addis Ababa, Ethiopia — Open to Remote
> whoami

Sup, I am a security researchers and a software engineer, I love to break things and just see how and to what level they function, I mostly focus on Offensive security at low-level to check if I can get buffer overflow on the and develop apps, websites, and API, but on my free time I try to make some digital arts like 3D designs, posters and drawings.

Project KASCVE

Automated Security Auditing Ecosystem & Penetration Tester

KASCVE is an automated security audit software for websites that tests your website for known CVE'S and Top 10 OWASP vulnerability with an addition of active penetration test such as SQL Injection and some others. A platform made for both desktop and android.

KiOS

Secure Linux Architecture

Architected a highly optimized, Arch-based Linux distribution engineered from the kernel up to drastically reduce attack surfaces while maintaining maximum developer velocity. Developed custom Python and Bash automation frameworks to handle system localization, automated provisioning pipelines, and granular cryptographic storage layouts.

Zero-Day Enumeration: Telegram Animation Engine

rlottie Media Engine Fuzzing Research

Independent remote research focused on stress-testing the rlottie media engine. Engineered an automated fuzzing harness utilizing AFL++ to execute systematic crash analysis, successfully isolating potential memory corruption vulnerabilities, input validation failures, and hidden memory leaks within third-party messaging integrations.

The-Donut

Terminal-Based 3D Rendering Engine in C++

Creative systems project implementing a 3D donut animation rendered entirely in the terminal using C++. Developed raw mathematical rendering algorithms and strict memory management constraints without relying on external graphical or rendering libraries.

Active Directory Exploitation

HTB Environments — WingData & Complex Corporate Labs

Exploited and compromised complex corporate Windows network lab environments. Utilized Impacket, Mimikatz, and Rubeus to execute advanced Kerberos authentication manipulation, AD Certificate Services (AD CS) exploitation, and Pass-the-Ticket (PtT) / Pass-the-Hash (PtH) techniques to harvest credentials and achieve absolute domain dominance.

LaloDev

Software Engineer

June 2025 — November 2025

Engineered and optimized backend software architectures within a formal Software Development Life Cycle (SDLC). Automated critical production infrastructure using Python, enforcing secure version control integrity and codebase hardening. Collaborated asynchronously with distributed teams to defend application logic against injection flaws and maximize server throughput.