Skip to content
View michspenz's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report michspenz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
michspenz/README.md

Michael Oscar

Offensive Security · Digital Forensics · Python Tooling


About Me

I'm a cybersecurity enthusiast operating across both sides of the security spectrum and breaking systems ethically as a penetration tester and reconstructing attacks as a digital forensics investigator. I build open-source security tools and document real-world offensive and forensic case studies.


Skills

Offensive: Web App Pentesting · Network Recon · Vulnerability Assessment
Burp Suite · Nmap · Metasploit · OWASP Top 10
Defensive: DFIR · EXIF/Metadata Analysis · Log Analysis · IOC Extraction
Chain of Custody · Incident Response · Threat Hunting
Languages: Python · Bash · JavaScript · C
Tools: Wireshark · Autopsy · Burp Suite · Nmap · VS Code · Git · Linux

Open to bug bounty collaborations, freelance penetration testing, forensic investigations, and security research partnerships.

Pinned Loading

  1. VulnnForgeVulnnForgePublic

    A modern hands-on web security training platform with intentionally vulnerable labs, guided writeups, and Dockerized environments.

    TypeScript 2

  2. KilnCoffeeKilnCoffeePublic

    An intentionally vulnerable Flask storefront demo for learning IDOR / broken object-level authorization.

    Python 2

  3. MetaData-AnalyzerMetaData-AnalyzerPublic

    Forensic metadata extraction tool for images (JPG, PNG, TIFF) and documents (PDF, DOCX) — generates structured JSON and CSV investigation reports.

    Python 2

  4. CSRF-PoC-GeneratorCSRF-PoC-GeneratorPublic

    A Python CLI tool that generates ready to use CSRF proof-of-concept HTML files for penetration testers and bug bounty hunters.

    HTML 2

  5. pentest-reportspentest-reportsPublic

    Professional penetration testing reports, vulnerability assessments, and offensive security writeups.

    2