Hi, I'm Gerard
I'm a security specialist with a strong focus on web applications. I've been working in the industry for more than 10 years, performing Web Audits and Penetration Testing, but also as a full stack developer.
In my spare time I do security research, bug bounties, participate in capture the flag competitions and contributing to open source projects.
Services
-
Pentest
-
Performing an in-depth analysis of your organization's security, vulnerabilities and weak points in all available environments and resources through a systematic testing process.
-
Web Security
-
Deep-dive manual penetration testing, reporting and follow up of your web applications and web services's vulnerabilities by following the WSTG OWASP procedures.
-
Red Team
-
Adversarial-based attack simulation to test the defenses of people, software and hardware of your organization, using real-life attack vectors.
-
Security Consultancy
-
Helping businesses identify critical and data assets, providing technical solutions and assisting complaying with the latest security certifications.
-
Workshops / Talks
-
Rising the security awareness of your company with security presentations, educating through workshops, organizing capture the flag events and performing internal phishing scenarios.
Experience
2019-Current | Freelance: Security Consultancy
|
2015-2021 | Endouble, Netherlands: Senior Security Specialist
|
2013-2015 | Technology in Live, Spain: Lead developer
|
2010-2013 | 3fera, Spain: Full Stack Developer
|
Projects
2021 |
SynScan
|
2021 |
Pass
|
2020 |
SigInt
|
2020 |
Salmon
|
2015 |
CMSDiff
|
Achievements
2019 |
8th Recon Village CTF @ DEFCON 27
|
2019 |
WPML - CSRF lead to RCE
|
2019 |
Speaker at II Tarragona Lawyer School Cyber Security Congress
|
2018 |
Microsoft Security Hall of Fame
|
2018 |
CCN-CERT CTF XII Finalist
|
2017 |
Hackron 2017 CTF Winner
|
2016 |
Speaker in Emerce Conference, Amsterdam
|
CVEs
CVE-2021-30126
|
CVE-2020-10568
|
CVE-2016-10990
|
CVE-2015-9412
|