Skip to content
View thezakman's full-sized avatar
🏡
Working from home
🏡
Working from home

Block or report thezakman

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
thezakman/README.md

TheZakMan

Pedro “TheZakMan” Araujo

Offensive Security · Vulnerability Research · Security Tooling

Security researcher, developer, CTF enthusiast and former graphic artist from Brazil.

Website LinkedIn Email Hack The Box


👋 About me

I’m an offensive security researcher with more than a decade of experience across technology, security, development and digital arts.

My primary focus is black-box application security, starting with little or no prior knowledge and working from reconnaissance to real-world impact.

  • 🔐 Web, API, Mobile and Cloud Security
  • 🧠 Vulnerability Research and exploit development
  • 🛠️ Creator of offensive security tools
  • 🚩 Co-founder of CTF-BR CTF-BR Flag
  • 🎨 Former Graphic Artist, Animator and VFX/Motion Designer
  • 🎸 Passionate about technology, music and art
  • 📚 Eternal student

From pixels to payloads.


🧠 Current focus

security_tooling:
  - Developing offensive security tools
  - Maintaining and improving existing projects
  - Shipping new features and performance updates
  - Expanding detection and exploitation capabilities
  - Researching new automation techniques

vulnerability_research:
  - Auditing web frameworks and their ecosystems
  - Discovering previously unexplored attack surfaces
  - Researching potential zero-day vulnerabilities
  - Analyzing vulnerability classes and exploitation primitives
  - Developing reproducible proof-of-concept exploits
  - Responsible vulnerability disclosure

research_areas:
  - Web Applications and APIs
  - Mobile Applications
  - Cloud Environments
  - Frameworks, libraries and dependencies
  - Authentication and authorization mechanisms
  - Vulnerability chaining and real-world impact

🛠️ Languages and tools

Languages and tools

Burp Suite Frida Nuclei Metasploit OWASP

🚀 Featured projects

Adaptive content discovery engine that fingerprints targets, learns from responses dynamically.

Fast IIS short filename enumeration tool with support for advanced target analysis and content discovery.

High-performance scanner for detecting exposed, residual and forgotten files on web servers.

📊 GitHub activity

GitHub statistics Most used languages

📡 WiGLE

WiGLE statistics

☕ Get in touch

WebsiteLinkedInGitHubEmailHack The Box

Security researcher by profession. Artist by nature. Eternal student by choice.

Pinned Loading

  1. CTF-Heaven CTF-Heaven Public

    💻 CTF Heaven

    Python 298 34

  2. internet-protocol_CTF internet-protocol_CTF Public

    Write-up for https://masterbootrecord.bandcamp.com/album/internet-protocol

    1

  3. OpenBucket OpenBucket Public

    A tool to dump all contents of an public/exposed/open bucket

    Python 1

  4. PathBreaker PathBreaker Public

    A professional path and header fuzzing extension for Burp Suite.

    HTML 4

  5. LeftOvers LeftOvers Public

    an advanced scanner for detecting leftover or residual files on web servers.

    Python 1

  6. dirChecker dirChecker Public

    Check all the day down if there is any directory list in any of the paths

    Python