~/portfolioOPEN TO INTERNSHIPS & JUNIOR ROLES

Rafael
Gálvez Silipo

Cybersecurity Student·Offensive Security·Red Team

I build security tools and research projects to understand how systems work, how they can be attacked, and how they can be secured.

01 — ABOUT

About Me

I started programming at around 10 years old, initially learning C# and Unity through game development. Over time, my curiosity shifted from creating games to understanding the systems underneath them — and that curiosity led me to cybersecurity and offensive security.

Today, I am studying Systems and Microcomputer Networks (SMR) and focusing my learning on Red Team, penetration testing, Active Directory, Windows/Linux, OSINT, malware research and AI-assisted cybersecurity.

I learn primarily by building. Instead of only using existing security tools, I create my own projects to understand the technologies and the problems behind them. My projects range from Red Team orchestration and C2 infrastructure to distributed systems, malware research and AI-driven security tooling.

My goal is to start my professional career in cybersecurity and eventually specialize in Red Team operations and offensive security research.

13+
public repositories
4
flagship security projects
1,300+
automated tests written
6+
years building software
02 — WHAT I DO

What I Do

Not a list of percentages — areas I actively work in, backed by the projects below.

Offensive Security

Understanding how systems are attacked — and how to defend them.

Red TeamPentestingActive DirectoryReconnaissanceOSINTPost-Exploitation

Security Engineering

Building the tooling an operator actually needs.

Security ToolingC2 ArchitectureAuthenticationRBACDetection EngineeringAutomation

AI × Cybersecurity

Using AI as a force multiplier — never as a blind autopilot.

Local LLMsAI AgentsRAGSecurity AutomationAI-assisted Research

Systems

The foundations everything else stands on.

LinuxWindowsNetworkingRustGoPythonC#
03 — FEATURED PROJECTS

Featured Projects

Four engineering projects — each one built to answer a real question about offensive security. Real screenshots, real usage, no mock-ups.

OrquestaRT — AI-assisted Red Team Orchestration PlatformActive researchFeaturedHover to preview

OrquestaRT

AI-assisted Red Team Orchestration Platform

A platform for orchestrating authorized Red Team operations through AI-assisted workflows — combining offensive security automation with human approval, scope enforcement and full auditability.

The full engagement cycle — scoping, OSINT, recon, Active Directory, post-exploitation, phishing, reporting — orchestrated by agents under a machine-readable ROE, with purple teaming as a first-class output.

587 automated tests
F0→F7 orchestration phases
26+ recon transports
PythonFastAPILangGraphNext.jsTypeScriptActive DirectoryOSINT+2
View Project10 sections
WorldC2 — Command & Control Platform for Authorized Security LabsActive researchHover to preview

WorldC2

Command & Control Platform for Authorized Security Labs

A C2 platform developed as a security research and learning project — focused on understanding command-and-control architecture, encrypted communications, session management and operator infrastructure.

Built to understand how modern C2 infrastructure is designed, secured and operated in controlled environments.

5 transport fallbacks
4 RBAC roles
14 browser E2E tests
GoVue 3NetworkingCryptographyC2SQLiteDocker
View Project10 sections
HiveMind — Distributed Multi-Agent Security ResearchActive researchHover to preview

HiveMind

Distributed Multi-Agent Security Research

A Rust-based experimental project exploring multi-agent coordination, distributed systems, concurrency, consensus and AI-assisted security research.

One of my most technically challenging projects — built to learn Rust and to explore how autonomous agents can coordinate under shared rules.

273 tests passing
9 crates in the workspace
0 TCP ports between agents
RustDistributed SystemsConcurrencyAIMLLinux
View Project10 sections
Wormy — Malware & Network Security ResearchResearch completeHover to preview

Wormy

Malware & Network Security Research

An experimental research project exploring malware behavior, network propagation and machine learning in isolated laboratory environments.

My first major malware research project — and one of the projects that shaped my interest in understanding offensive techniques from the inside.

525 automated tests
44 gated exploit modules
15 lab services (127.0.0.1)
PythonMachine LearningNetworkingDockerSecurity Research
View Project10 sections
05 — HOW I LEARN

How I Learn

I learn by building.

When I want to understand a technology or a security concept, I try to implement it myself. Building these projects forces me to understand the systems underneath the tools I use, to experiment with different approaches and to learn from failures.

I also use AI as a development and research assistant, but I treat generated code as something to review, test and understand — not something to blindly trust.

My goal is not just to make something work, but to understand why it works.

06 — SKILLS

Technical Skills

Only tools and technologies I have actually used in real projects.

Languages

primary → comfortable
PythonC#GoRustTypeScriptBashPowerShell

Security

offensive focus
Red TeamPentestingActive DirectoryOSINTC2Reconnaissance

Systems

daily drivers
LinuxWindowsNetworkingDocker

Security Research

lab-first
Malware ResearchAI/ML SecurityAutomationPurple Team

Tools / Ecosystem

hands-on
GitGitHubMITRE ATT&CKBloodHoundNeo4jMISPHack The Box
07 — CERTIFICATIONS

Certifications

Obtained

Foundation level

eJPTv2 — Junior Penetration Tester

INE Security

Previously certified · Expired July 2026

Networking Fundamentals

Cisco Networking Academy

Relevant coursework completed

Offensive Security Training

Hack4u

Red Team & pentesting coursework

Currently working towards

Next professional milestones

CRTO

Red Team Operator training path

Preparing

Deepening adversary emulation and Red Team tradecraft.

CPTES

Penetration Testing training path

Preparing

Structured preparation for professional penetration testing certifications.

No logos shown as if already earned — only what is real.

08 — LABS & TRAINING

Labs & Training

Theory is nothing without hands-on practice.

Hack The Box

Building experience through practical labs and realistic attack scenarios — active machines, AD paths and CTF-style challenges.

Personal Labs

Self-built isolated environments: Active Directory domains, deliberately vulnerable services, C2 infrastructure and detection tooling — where every project on this page runs.

Purple Team Practice

Validating offensive work against detection: Sigma rule authoring, VECTR-style tracking and ATT&CK coverage measurement.

09 — ACHIEVEMENTS

Achievements

Evidence that goes beyond code.

ASTI Challenge — National Robotics Finalist

Team Captain · 1st place Málaga · Spain National Final

Team Captain1st place — MálagaNational Finalist

Captain of a robotics team that finished first in Málaga and qualified for the national final in Spain.

Worked on robot development, problem-solving, team coordination and competition strategy — under real time pressure and against the best teams in the country.

// leadership · teamwork · competition strategy — skills that don't show up in a git log

10 — EDUCATION

Education

2025 — PresentIn progress

SMR — Sistemas Microinformáticos y Redes

DigitechFP

Systems administration, computer networks, operating systems and cybersecurity fundamentals — the formal backbone of my self-taught path.

2020 — 2024Completed

Video Game Programming — C# / Unity

EVAD

My entry door to programming: C#, Unity and the discipline of shipping playable software. The curiosity about how things worked under the hood started here.

11 — CURRENT FOCUS

Currently Focused On

Last updated — September 2026
01

Red Team & Pentesting

Deepening practical offensive security skills: methodology, tradecraft and hands-on labs.

02

Certifications

Preparing for CRTO and CPTES as the next professional milestones.

03

Active Directory

Improving Windows and enterprise environment attack methodology — from enumeration to domain dominance.

04

Hack The Box

Building experience through practical labs and realistic attack scenarios.

05

Security Tooling

Continuing to build and refine offensive security research projects.

12 — CONTACT

Let's connect

I'm interested in internships, junior cybersecurity opportunities and projects related to offensive security and Red Team.

Usually replies within 24 hours
Email
rafagasi09@gmail.com