Skip to content
View ParzivalHack's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.

Block or report ParzivalHack

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ParzivalHack/README.md

Tommaso Bona

Cybersecurity Professional & Entrepreneur

Welcome

As a passionate cybersecurity professional and entrepreneur, I'm the Co-Founder, Board of Directors' Member, and Major Stakeholder at Voyxa. My work is focused on revolutionizing the IT helpdesk field with innovative, AI-driven solutions. In my free time, I am an independent bug bounty hunter and security researcher, contributing to the security of tools and libraries. I also serve as an OSINT Analyst with the Guardian Group's elite PURSUIT® Team, dedicated to fighting sex trafficking and child exploitation.

My background as a Cybersecurity Specialist and SOC Analyst has provided a strong technical foundation, which I now leverage to build secure and scalable systems, conduct security research, and lead technical teams.


💡 What I'm Focused On

  • Leadership & Technical Team Management: During my tenure as CTO, I led a 20-person cross-functional team, which included a 24/7 SOC, Legal IT paralegals, GRC experts, a Full Stack department, AI/ML, DevOps, and DevSecOps.
  • Cybersecurity & Bug Bounty Hunting: Specializing in offensive security, vulnerability research, and advanced adversarial AI testing, with a passion for discovering and reporting vulnerabilities.
  • Humanitarian OSINT: Applying my skills as an OSINT Analyst to support law enforcement in crucial anti-trafficking operations.
  • Security Research & Publications: Investigating emerging threats and publishing research on topics such as secure data transmission and AI offensive security.

🛠️ My Expertise

Core Skills

🔹 Cybersecurity: Offensive Security, Threat Analysis, Penetration Testing (Web & Network), Digital Forensics, and OSINT. 🔹 AI Security: LLM Red Teaming, Prompt Injection, Adversarial Machine Learning, and Automated Security Assessments. 🔹 Leadership & Management: Technical Team Management, Product Management, and Project Management. 🔹 Development & Scripting: Python, PowerShell, Bash, and developing custom security tools.

Publications & Projects

  • Research Paper: Fragmentation, Encryption, and Redundancy in Data Transmission: A Novel Secure UDP-Based Fragmentation Protocol (Published via CERN & OpenAIRE).
  • Project: LPEAssessor, a comprehensive Linux privilege escalation VAPT Framework.
  • Articles: Author of multiple articles on cybersecurity for StationX Ltd. and SecurityCert, covering topics from SQL Injections to AI Offensive Security.

Core Security Contributions

CPython:

I identified and addressed a Path Traversal vulnerability,in a core test suite of the CPython (the official Python Programming Language) project. This fix, which improved the integrity of the codebase, was submitted via a pull request and merged after a thorough review by core developers. My work involved developing a proof-of-concept (PoC) to demonstrate the vulnerability and collaborating with the Python Security Response Team (PSRT) to report it:

Fix Path Traversal in multissltests.py

Licenses & Certifications

I hold a wide range of certifications from globally recognized vendors, demonstrating my commitment to continuous learning and excellence.

  • ISC2: Certified in Cybersecurity (CC), NIST Cybersecurity Framework 2.0.
  • EC-Council: E|HE, N|DE, D|FE.
  • Security Blue Team: Blue Team Junior Analyst (BTJA).
  • Fortinet: Fortinet Certified Associate in Cybersecurity.
  • IBM: Cybersecurity Roles, Processes & Operating System Security.
  • ESET: Certified ESET Managed Cloud Security Specialist.
  • ESET: Certified ESET Managed Client Security Specialist.
  • AWS: Authentication and Authorization with AWS IAM, AWS Foundations: Securing Your AWS Cloud.
  • SkillFront: ISO/IEC 27001:2022 Information Security Associate.

🌐 Connect & Collaborate

I'm always open to discussing new opportunities, projects, and the future of cybersecurity and AI innovation.

LinkedIn Badge Gmail Badge


📊 GitHub Stats

Click here for GitHub Stats

GitHub Stats
Top Language

Pinned Loading

  1. Poison-MASSReporter Poison-MASSReporter Public

    This script is a PyQt5-based application that performs a Mass Reporting Attack on any TikTok profile, resulting in a ban for most of them.

    Python 87 14

  2. T-DoS T-DoS Public

    Denial of Service tool by ParzivalHack

    Python 27 6

  3. BruteCam BruteCam Public archive

    Tool with a huge database of hacked CTV Cameras, sorted by country.

    Python 31 2

  4. T-XSS T-XSS Public

    XSS vulnerability scanner written in Python

    Python 16 2

  5. Proxy-Inspector Proxy-Inspector Public

    Proxy Inspector is a Python tool that can be used to check the validity and anonymity of any existining proxy

    Python 6

  6. Octo-Miner Octo-Miner Public archive

    ETH Miner made in Python with the infura.io web3 infrastructure

    Python 8 1