Skip to content
View SulfurPT's full-sized avatar

Block or report SulfurPT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
SulfurPT/README.md

👋 Hey

Pentester transitioning into Web3 Security, currently focused on mastering Solidity, EVM internals, and DeFi protocols.
Building a portfolio through CodeHawks First Flights, private audits, contests, bug bounties, and deep technical research.

Pentester | Web3 Security Researcher | Smart Contract Auditor (in training)


🧩 Background

  • 🧠 15+ years of experience in IT, from Help deskLinux SysAdminDevOpsPentester/PTaaSOffensive Security Manager.
  • ⚙️ Strong background in automation, scripting, and infrastructure management (Python, Bash, C/C#).
  • 🔒 5+ years in Offensive Security, including PTaaS, Vulnerability Research, and Red Teaming.
  • 🧱 Currently focused on Smart Contract Auditing and DeFi protocol security, bridging Web2 expertise with Web3 technology.

🧰 Tech Stack

Web3 / Smart Contract Auditing

  • Solidity · Foundry · EVM
  • Auditing production-ready smart contracts and research-driven blockchain projects
  • Gas optimization, security best practices, and vulnerability analysis
  • Participation in CodeHawks First Flights, Private Audits, Contests

Security & Auditing Tooling

  • Fuzzing & Formal verification · Slither · Aderyn · Echidna
  • Threat modeling, architecture review, and PoC development for on-chain security

Pentesting / Offensive Security (condensed)

  • PTaaS (Pentesting-as-a-Service) · Web apps · APIs · Cloud · Internal · External · Wi-Fi · Mobile
  • Python · Bash · C · C# · Linux · Windows
  • Methodologies: PTES, OWASP; reporting, remediation planning

🎓 Certifications & Courses

🧠 Cyfrin Updraft

Blockchain Basics Course

Solidity Smart Contract Development

Foundry Fundamentals

Advanced Foundry

Smart Contract Security


🚀 Encode Club

EVM Bootcamp

Advanced Solidity Bootcamp


🧩 Smart Contract Hacking (SCH)

Currently in progress
smartcontractshacking.com


🔬 Current Focus

  • Enrolled in Smart Contract Hacking (SCH) to deepen exploit development and auditing skills
  • Building a deep understanding of on-chain risk surfaces
  • Analyzing real protocol vulnerabilities and creating PoCs
  • Preparing for formal Web3 security audits (Code4rena / Sherlock / Cantina)

📂 Key Repositories


📫 Connect with Me


“Breaking things to make them safer.”

Popular repositories Loading

  1. Security_Audits Security_Audits Public

  2. CodeHawks-First-Flight CodeHawks-First-Flight Public

    Solidity

  3. SulfurPT SulfurPT Public