Skip to content
View olawajudev's full-sized avatar

Block or report olawajudev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
olawajudev/README.md

👤 Ibrahim Ayoola

VAPT Specialist (Vulnerability Assessment and Penetration Testing) | Web • Network • AD/Windows • Mobile • Cloud Security

🔐 Advanced vulnerability assessment & penetration testing across full attack surfaces. Focused on structured methodology, CVSS-aligned risk reporting, and secure remediation guidance. All testing conducted in authorized, isolated lab environments only.

🎓 TryHackMe: https://tryhackme.com/p/wajudev | 💼 LinkedIn: https://linkedin.com/in/olanrewaju-ayo


🛡️ Core Expertise

Domain Key Focus
Web App OWASP Top 10/API Top 10, Auth bypass, IDOR, JWT, SSRF, Business Logic
Network Service enumeration, CVE validation, Privilege escalation, Lateral movement
AD/Windows Kerberoasting, BloodHound mapping, GPO abuse, Domain escalation paths
Mobile APK reverse engineering, insecure storage, root bypass, API hooks
Cloud IAM misconfig, S3 exposure, metadata SSRF, container escapes

📂 Featured Projects (Lab-Only)

Project Description Link
🔍 AutoRecon-X Modular recon pipeline: Nmap + Gobuster + Nuclei → structured JSON View Repo
📄 Web App Pentest Report Professional engagement deliverable: 7 findings, CVSS v3.1, PoC, remediation View Report
🌐 VAPT Lab Portfolio Isolated environment write-ups: AD escalation, Cloud IAM, Mobile hooks View Labs

📜 Methodology & Compliance

  • OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK
  • CVSS v3.1 scoring, risk prioritization, remediation validation
  • Executive + technical reporting, secure SDLC integration

🔗 Connect

📧 wajudev@gmail.com | 💼 LinkedIn | 🎓 TryHackMe

⚠️ Ethics Disclaimer: All code, reports, and demonstrations are for portfolio purposes only. Testing performed exclusively in isolated, authorized lab environments (OWASP Juice Shop, Metasploitable, TryHackMe). No production or unauthorized systems were targeted.

Pinned Loading

  1. vapt-practice-engagement vapt-practice-engagement Public

    Python 1

  2. vapt-webapp-report vapt-webapp-report Public

  3. autorecon-x autorecon-x Public

    Python

  4. olawajudev olawajudev Public