Skip to content
View njeru-codes's full-sized avatar

Organizations

@SpaceyaTech@Durrafx-repos

Block or report njeru-codes

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
njeru-codes/README.md
Typing SVG

PortfolioLinkedInHackerOneEmail


whoami

$ cat profile.txt

Offensive Security Engineer and Penetration Tester based in Nairobi, Kenya.
Expertise in bug bounty research, vulnerability & malware research, and red team operations.
I find the gaps before attackers do — then help organizations close them for good.


🔭 Currently

  • 🔴 Red teaming payment & authentication platforms at Durrafx
  • 🐛 Hunting bugs across web, API, and mobile targets on HackerOne
  • 🔐 SOC operations & log analysis at Foresight Tech Group
  • 📖 Deepening expertise in mobile app security and malware analysis

🛠 Skills & Tools

Offensive
Penetration TestingRed TeamingBug BountyVulnerability ResearchMalware AnalysisSocial Engineering

Domains
Web SecurityAPI SecurityMobile SecurityNetwork SecurityFinancial Systems

Frameworks & Standards
OWASPPTESPCI-DSSMITRE ATT&CK

Languages & Tools
PythonGoBashBurp SuiteDockerMetasploitWiresharkNmapSIEM

Defensive
Log AnalysisIncident ResponseThreat ModelingIDS/IPSSecure Code Review


📊 GitHub Stats

activity-graph

statslangs

trophy graph

📌 Featured Projects

ProjectDescriptionStack
ARPARP spoofing tool — intercepts DNS traffic and exfiltrates to a remote serverPython, Scapy
PhoneBook-VaultAll possible Kenyan phone number combinations for OSINT/recon useData
Note-WeaveMinimal, elegant note-taking appJavaScript

🖊️ Writeups & disclosures coming soon — follow to stay updated.


🤝 Let's Work Together

$ cat availability.txt
✓ Open to penetration testing engagements
✓ Available for red team operations ✓ Bug bounty collaborations welcome
✓ Security consulting & advisory

📬 Reach me at njerumtwaiti@proton.me or connect on LinkedIn.


"unlocking the undetectable."

profile views

Pinned Loading

  1. ARPARPPublic

    Always Reading Packets (A.R.P) is ARP spoffing tool using Scapy to intercept DNS traffic and exfiltrate it to a remote server

    1

  2. PhoneBook-VaultPhoneBook-VaultPublic

    This repository contains a collection of all possible combinations of Kenyan phone numbers

    1

  3. Note-WeaveNote-WeavePublic

    a simple, elegant note-taking app built for everyday use. Just start writing

    JavaScript