Skip to content
View itssherwin's full-sized avatar

Block or report itssherwin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
itssherwin/README.md

Hi, I'm Sherwin πŸ‘‹

Cyber Security Engineer / Penetration Tester with 4+ years of hands-on experience
Web, Network, and Active Directory security assessments

πŸ” What I Do

  • Web, network, and internal penetration testing (enterprise & government systems)
  • Active Directory security reviews, privilege escalation, and credential abuse
  • Vulnerability exploitation with clear remediation and re-test validation
  • Phishing simulations and offense-driven security assessments

πŸ› οΈ Core Skills

  • Offensive Security: Web & Network Pentesting, AD Security, Exploitation
  • Tools: Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Nessus
  • Tech: Linux, Windows, Active Directory, Networking, REST APIs, Python
  • Standards: OWASP Top 10, secure configuration review

🎯 Current Focus

Internal security automation, bug bounty workflows, and advanced AD attack paths.

🌐 Links

Pinned Loading

  1. MoneroMiner MoneroMiner Public

    xmrig compiled with 0% dev fee

    Shell 1

  2. BasicAuthBruteForcer BasicAuthBruteForcer Public

    Http Auth BruteForcer Tool Written in GoLang Supports both Basic and Digest authentication types

    Go

  3. IPFinder IPFinder Public

    Finds server IP behind the WAFs or Cloud services

    Python 1

  4. phishing-demo phishing-demo Public

    Educational phishing awareness demo

    Python