operator@offsec — session

bb@sec:~$ whoami

Belizaire
Bassette II

Junior Penetration Tester // Offensive Security

I break into web apps, networks, and APIs the way an attacker would — then turn every finding into clear, reproducible reporting that helps teams fix what matters. Driven to secure the digital world by understanding threats before they strike.

Available for engagements & full-time roles
bb@sec:~$ cat whoami.md

whoami

whoami.md

I'm an offensive security practitioner and Junior Penetration Tester with hands-on experience running web application and network security assessments inside a PTaaS consulting environment. Across 5 client engagements I identified 73 vulnerabilities — including high-impact IDOR, XSS, and Arbitrary File Upload findings — each documented with proof-of-concept exploits, CVSS ratings, and actionable remediation. I was promoted from intern to Junior Penetration Tester on the strength of consistent, high-quality findings and professional reporting.

0
Vulnerabilities identified
0
Client engagements
0
Certified (OSCP & BSCP in progress)
// findings breakdown — 5 engagements
Info Disclosure26
XSS10
Missing Sec Headers9
IDOR7
Arbitrary File Upload3
CSRF2
Mass Assignment1

+ specialized findings: CSV/XLSX formula injection · insecure password-recovery workflow · username enumeration

bb@sec:~$ ls -la ./arsenal

Arsenal

Tools, languages, and methodologies I use across the full assessment lifecycle — recon → exploitation → privilege escalation → reporting.

# Recon & Scanning

NmapNessusOpenVAS AmassGobusterdirb

# Web & API

Burp Suitesqlmap wpscankatana

# Active Directory & Post-Ex

CrackMapExecBloodHoundKerbrute ResponderImpacketEvil-WinRM

# Passwords & Exploitation

HydraHashcatMetasploit

# Languages & Scripting

PythonBashSQL

# Operating Systems

Kali LinuxLinuxWindows

# Techniques

Web App TestingNetwork Enumeration Privilege EscalationActive Directory Exploitation API TestingExploit Chaining

# Frameworks & Standards

OWASP Top 10MITRE ATT&CK NIST CSFCVSS

# Reporting & Delivery

PoC DevelopmentCVSS Risk Rating Reproduction StepsRemediation Guidance Client Deliverables
bb@sec:~$ tail -f experience.log

Experience

Junior Penetration Tester (promoted from Intern) Dec 2025 – Present
Maltek Solutions LLC · Remote · PTaaS consulting
  • Promoted from Penetration Testing Intern to Junior Penetration Tester based on engagement performance and the quality of vulnerability findings and client deliverables.
  • Conducted black-box and gray-box penetration tests across 5 web application engagements, identifying 73 total vulnerabilities.
  • Discovered and validated high-impact findings — 7 IDOR, 10 XSS, 3 Arbitrary File Upload, 2 CSRF, 1 Mass Assignment — each with documented proof-of-concept exploits demonstrating business impact.
  • Identified 26 Information Disclosure instances and 9 Missing Security Header misconfigurations, directly reducing client attack surface.
  • Uncovered specialized issues including CSV/XLSX formula injection, insecure password-recovery workflow, and username enumeration — depth across OWASP Top 10 categories.
  • Delivered professional reports per engagement with CVSS risk ratings, reproduction steps, and remediation guidance for client dev and security teams.
IT Risk Management Apprentice May 2024 – Dec 2024
Independent Pulmonary Therapy Services
  • Performed HIPAA-aligned access control and policy audits across healthcare IT systems.
  • Assisted with secure handling and classification of sensitive patient health information (PHI).
bb@sec:~$ ./run_engagements --list

Engagements & Labs

Selected hands-on work — from client-style methodology to CTF-grade exploitation. Click a card for the attack chain; full reports open as PDFs. All testing performed with explicit authorization.

~/boot2root · tryhackme
🐧LFI → RCE → root
Linux · Web Exploitation

Archangel — Full Attack Chain

Chained an LFI to unauthenticated RCE via log poisoning, then escalated to root through cron abuse and PATH hijacking.

TryHackMeLFI→RCELinux PrivEsc
↗ view detailsPDF report
🪟domain compromise
Active Directory · Windows

Attacktive Directory — AD Attack Path

Enumerated a Windows domain, abused AS-REP Roasting to recover creds, and pivoted to domain compromise via DCSync + Pass-the-Hash.

KerbruteAS-REP Roastingsecretsdump
↗ view detailsPDF report
~/network security
🧱recon → remediation
Firewall · Enterprise Network

pfSense Firewall Penetration Test

Assessed a Windows enterprise network behind pfSense — white-box & black-box — then hardened policy and re-scanned to confirm fixes.

NmapNessusOpenVASDMZ
↗ view detailsPDF report
📡findings & fixes
Kali Linux · Nessus

Network Vulnerability Assessment

Enumerated ports, services, and misconfigurations from Kali; triaged critical/high/medium findings and mapped each to concrete remediation.

Vulnerability ScanningTriageReporting
↗ view detailsPDF report
~/web & api
🔑BOLA / IDOR
API Security · REST

API Pen Testing — BOLA / IDOR

Tested REST APIs for broken object-level authorization, excessive data exposure, and weak access control via JWT manipulation and object-reference tampering.

RESTJWTAccess Control
↗ view detailsclient-style
🔓auth attack
Web App · DVWA

DVWA — Brute-Force Exploitation

Intercepted login requests with Burp, automated credential guessing with Hydra, and documented defenses: MFA, lockout, rate limiting.

Burp SuiteHydraAuth Hardening
↗ view detailsPDF report
~/adversary simulation & blue team
☣️full lifecycle
Offensive & Defensive

Ransomware Attack Simulation

Built a dropper, delivered via phishing, executed payload to encrypt files, then recovered with a private key — mapping the full lifecycle end to end.

Phishing SimEternalBlueIncident Response
↗ view detailsPDF report
🛰️SOC triage
Blue Team · SIEM

CNY Hackathon — Cybersecurity Track

Performed SOC-style alert triage and log analysis on simulated SIEM data; identified IOCs including suspicious IP activity and authentication abuse.

SIEMLog AnalysisIOC
↗ view detailscompetition
🚩team defense
Blue Team · Collegiate Competition

NCAE Cyber Games — Regionals

Represented Syracuse University in the NCAE Cyber Games regional round — a national, team-based cyber-defense competition, hardening and defending live services against an active red team.

Syracuse UniversityCyber DefenseIncident Response
↗ view detailscompetition
~/cryptography
🔐confidentiality & integrity
Crypto · Key Management

Encryption & Key Management

Implemented symmetric & asymmetric encryption with OpenSSL, GPG/Kleopatra, and WinSCP to encrypt, sign, transfer, and verify data across systems.

OpenSSLGPGSFTP
↗ view detailsPDF report
bb@sec:~$ cat certs.json

Certifications

🎖️
eJPT
INE — eLearnSecurity Junior Penetration Tester
● earned
🎯
OSCP
Offensive Security Certified Professional
◐ in progress
🕸️
BSCP
PortSwigger — Burp Suite Certified Practitioner
◐ in progress
🤖
AI-300
OffSec — AI Security & Exploitation
◐ in progress
~/education
education.txt
Syracuse University Expected May 2026
B.S. Information Management & Technology · Concentration: Information Security · Minor: Computer Science
bb@sec:~$ ./contact --open

Contact

connect.sh

Open to full-time offensive security roles, internships, and authorized security assessments. Let's talk.

Ethical note: I only test assets with explicit authorization or within approved programs.

status  : open to work
location: Syracuse, NY
role    : Jr. Penetration Tester
focus   : Web · Network · API
certs   : eJPT · OSCP · BSCP