Open to work
@Azyven
Web pentester & vulnerability researcher
I test web applications and dig for vulnerabilities. On the side I build HunterFr, a CTF platform, and HuntCode, the editor behind it.
- Web Pentesting
- Vulnerability Research
- Full-stack Development
- System Administration
I'm Azyven, a self-taught web pentester
I never went to school for this. I learned by building projects and breaking them, and I still work both sides: I develop full-stack web applications, and I test them for the flaws that actually show up.
- Learned
- Self-taught, no school
- Focus
- Web application security
- Side project
- HunterFr, a CTF platform
- Also
- Full-stack development
- Scope
- Authorised targets only
- Discord
- vzwj
Skills
Picked up on my own, in that order.
Web application testing
Working through an application by hand to find where its own rules stop being enforced: access control, injection, authentication and session handling.
- Burp Suite
- Caido
- ffuf
- Nmap
- SQLMap
- Wireshark
Vulnerability research
Reading source code to find the bug before anyone triggers it, then reproducing it from a clean state and reducing it to the smallest proof of concept.
- Source review
- PoC
- OWASP
- CVE
- Python
Patching & remediation
The part that makes it worth doing: writing the fix, not just the report. I patch what I find, and I check the patch actually closes the hole.
- Secure defaults
- Code review
- Regression testing
Full-stack development
Building the applications, not only testing them: interface, API, database and deployment, in TypeScript from end to end.
- TypeScript
- React
- Next.js
- Node.js
- PostgreSQL
- TailwindCSS
Infrastructure & hardening
Running the machines under my own projects: Linux, containers, reverse proxies, TLS, backups, and isolation that assumes something will get through.
- Linux
- Docker
- Nginx
- Proxmox
- Bash
- Git
Reporting
Writing findings for the person who has to ship the fix: impact, reproduction steps, evidence, and a remediation they can apply the same day.
- Reporting
- Documentation
- Disclosure
Projects
Side projects, built and run end to end.
- Live
HunterFr
CTF platform
A capture-the-flag platform for people getting into security. Challenges across web, reverse engineering, cryptography and forensics, ordered so progress actually goes somewhere instead of throwing beginners at a wall.
- Next.js
- TypeScript
- TailwindCSS
- PostgreSQL
- Docker
- Nginx
- Linux
- In development
HuntCode
In-browser code editor
The editor and execution environment behind HunterFr's challenges. Writing code in a browser tab is the trivial part; running a stranger's code without handing them the host is the actual project.
- TypeScript
- Next.js
- Node.js
- Docker
- Linux
- WebSockets
Experience
What I have been doing, and since when.
- 2026 →
Web pentesting & research · Self-taught · authorised scope only
Web application testing, entirely self-taught and entirely legal: my own platforms, public labs, CTF targets, and third-party applications only under written authorisation. Every finding comes with reproduction steps and a proof of concept.
- Burp Suite
- Caido
- ffuf
- OWASP
- 2026 →In progress
Creator & sole developer · HunterFr · side project
A CTF platform I built and run on my own time: the product, the whole codebase, the database and the servers. I write the challenges and keep the containers that run them from becoming the way in.
- Next.js
- PostgreSQL
- Docker
- Linux
- 2026 →In progress
Architecture & development · HuntCode · side project
Designing the in-browser editor and execution sandbox behind HunterFr's challenges — short-lived containers, stripped capabilities, no egress, and a startup budget small enough to feel local.
- TypeScript
- Node.js
- Docker
- WebSockets
Writing
Notes and write-ups on web security.
