Skip to content
View marcostolosa's full-sized avatar
🏴‍☠️
Mem3nt0 Mori.
🏴‍☠️
Mem3nt0 Mori.

Sponsoring

@tmux

Block or report marcostolosa

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
marcostolosa/README.md

👋 Hello friend, I'm Marcos Tolosa (aka Tr0p)

Typing SVG

I'm a red teamer, pentester, bug bounty hunter, reverse engineer and I really like automating the boring part. My brain is wired differently (ASD Level 1), giving me the hyperfocus needed to dismantle complex threats and then teach others how they tick. I don't just find vulnerabilities; I tear them apart to understand their core.

  • I don't just hack; I teach what I learn: Offensive techniques, binary reversing, and application security, etc - from the attacker's perspective.
  • Always hunting: When I'm not on an engagement, you'll find me owning boxes on HTB, THM, researching with BugCrowd, HackerOne, Intigritti and learning more from pwn.college, malops and pretty much any other platform worth its salt (Crackmes.one, MalwareBazaar, DEFCON, etc.).

🛡️ Vulnerability Research & Disclosures

  • CVE-2025-10230 (CVSS 10.0): Discovered a critical OS Command Injection vulnerability in Samba hidden for 13 years.
  • CVE-2025-67503 (CVSS 8.2): Discovered a high Cross-Site Scripting (XSS) Reflected vulnerability in WeGIA platform.
  • Samba CTDB: Reported a Buffer Overflow vulnerability in the InfiniBand wrapper due to unsafe string handling.

🌐 Socials:

DiscordLinkedInGmailTwitchTwitterYouTube


💻 Tech Stack:

GoMarkdownPowerShellPythonShell ScriptWindows TerminalAWSAzureDigitalOceanGoogle CloudApacheNginxDocker

🧠 My Playground

  • Red Teaming & APT Emulation

  • Exploit Development & Reverse Engineering

  • AI/ML in Offensive Security

    • Authored Tools: ARCTAX, MANW-NG, riskIA-service, OSCP Insights, REload.Me, etc.
  • Advanced AppSec & DevSecOps

  • Cloud Security & Secure Architecture

  • My Go-To Stack:

    • Heavy Hitters: BurpSuite Pro, pwntools, Frida, Radare2/Rizin, Ghidra, IDA Pro, x64/x32dbg, Impacket, ffuf, naabu/nuclei, Nmap, CrackMapExec, BloodHound, tshark, Havoc, Cobalt Strike, mitmproxy.
    • Languages of Choice: Python for everything, Bash and PowerShell for speed, C/C++ when I need to get close to the metal and JavaScript to run everywhere.
    • Techniques: If it can be scripted, I automate it. Advanced Regex, Semgrep, CodeQL, and custom scripts are part of my workflow.

Haze-LinuxHaze-PythonHaze-PowershellHaze-BashHaze-CHaze-NmapHaze-JavaScriptHaze-BurpHaze-GitHubActionsHaze-TmuxHaze-GolangHaze-CloudflareHaze-mysqlHaze-terraformHaze-seleniumHaze-tensorflowHaze-scikitlearnHaze-metasploitHaze-vimHaze-kubernetesHaze-AndroidHaze-AppleHaze-HuggingFaceHaze-OpenSourceHaze-WiresharkHaze-PepeHaze-KaliHaze-ObsidianHaze-VirusTotalHaze-Pandas

snake gif


Profile Views

Pinned Loading

  1. manw-ngmanw-ngPublic

    A command-line tool for extracting Win32 API documentation from Microsoft and exec this functions.

    Python 14 2

  2. OCRackOCRackPublic

    High-performance PDF translation tool featuring PaddleOCR for maximum text extraction with optimized prompts, automatic chapter detection, smart chunking, checkpoint/resume system, and comprehensiv…

    Python 6 2

  3. arctaxarctaxPublic

    AI bypass prompt generator with ML + Uncensored local LLM.

    Python 4

  4. mindsecurity/REload.Memindsecurity/REload.MePublic

    REload.Me – The most easy reverse engineer classroom.

    Python 1

  5. SecListsSecListsPublic

    Forked from danielmiessler/SecLists

    SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strin…

    PHP 1 1

  6. LeakHoundLeakHoundPublic

    Automated security scanner engineered to detect and validate exposed secrets across web infrastructures and local codebases.

    Python 1