$ ./thesecurityvault --init

The Security Vault

Because Security Matters - Deep dives for security defenders

scroll to explore

$ tail -n 6 /var/log/vault/research.log

Blog Posts

view all →

$ ls -la ~/projects

Projects

// tools and resources I've built

OrgSec Guide

OrgSec Guide

A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity program.

XXExploiter

XXExploiter

Tool to help exploit XXE vulnerabilities. Generates XML payloads and automatically starts a server to serve DTDs or perform data exfiltration.

MirageVM

MirageVM

JavaScript virtual machine for code obfuscation. Protects sensitive client-side logic with custom bytecode through a low-level language that supports all JavaScript features. (Private project)

Living of the Code (LOC)

Living of the Code (LOC)

A curated list of attack techniques that target software developers in their natural habitat: code.

VSCode Swissknife

VSCode Swissknife

Scriptable VS Code extension to generate or manipulate data. Stop pasting sensitive data into webpages.

Watchtower

Watchtower

VS Code extension that scans your workspace for malicious configurations, invisible Unicode threats, and dangerous IDE attack vectors — fully local, fully open source.

Warden

Warden

Enforce file-based policies on managed machines by automatically detecting and correcting config files that drift from approved values.

DamnVulnerableCryptoApp

DamnVulnerableCryptoApp

An app with intentionally insecure crypto. Perfect for testing and exploiting weak cryptographic implementations and learning crypto without diving deep into the math.

Coup Sheet

Coup Sheet

If you like the board game Coup as much as I do, you'll find this sheet super helpful.

How To Test Api Keys

How To Test Api Keys

A visual, interactive cheat-sheet for testing whether leaked API keys and secrets are still valid — pick a service and get a ready-to-run command.

Luís Fontes

Luís Fontes

Principal Product Security Engineer

My current work focuses on keeping a bank secure. Over the past few years I've been challenging how security teams work, shifting practices and mindset to keep pace with a threat landscape reshaped by AI.