~/about

root@0xGaphy:~$ whoami

Raji Abdulgafar

I break things in controlled environments so they don't break in production. This blog is where I document what I learn along the way, vulnerabilities I chase, systems I dissect, and the occasional tool I build to make the process faster.

> background

Cybersecurity engineer with hands-on experience across pentesting, red teaming, vulnerability assessments, and digital forensics — 70+ engagements spanning fintech, healthcare, telecom, banking, and government sectors.

> what_i_do

Offensive Security • Penetration Testing • Red Team • OSINT • CTF • Digital Forensics

> what_you'll_find_here

Writeups, methodology notes, tools, payload references, and lessons pulled from labs, engagements, and real-world-like scenarios. Occasional Bash/Python automation, because doing things twice by hand is a bug, not a feature.

> projects

Built r3con1z3r, an OSINT recon tool now shipped with the SecBSD and Tsurugi Linux distros.

> philosophy

Security isn't a checklist. It's understanding how and why systems fail, then closing the gap before someone else finds it.

> ethics

Everything documented here is intended for authorized labs, CTFs, and educational purposes only.

> elsewhere

root@0xGaphy:~$ while true; do break; understand; repeat; share; done