// page

Projects

Selected work

Things I built, broke, or defended

Academic and internship projects across the offensive stack, from a live aviation CTF I co-engineered at EUROCONTROL to honeypots, mobile pentesting and full security audits. Write-ups for several of these are in progress.

Internship · EUROCONTROL EATM-CERT

Aviation CTF for 113 players

Co-engineered a capture-the-flag competition themed around aviation systems, played by 113 participants from across the European aviation sector. Designing challenges is the inverse of solving them: every puzzle has to be unambiguous, solvable by the intended path, and resistant to unintended shortcuts.

Alongside the CTF: penetration testing of aviation systems and applications, plus R&D supporting aviation cybersecurity.

FEB-MAY 2025 · BRUSSELS · CTF DESIGN · PENTEST
Security audit

Full audit: company & pharmacy

End-to-end security assessment of two organisations: OSINT reconnaissance, technical penetration testing, a phishing simulation campaign, and a staff awareness survey. The human layer turned out to be the shortest path in, which is usually the case and rarely the part that gets budgeted.

OSINT · PENTEST · PHISHING · AWARENESS
Detection lab

Honeypot lab: red vs blue

Deployed honeypot servers with Kibana dashboards to capture and visualise attacker behaviour, then ran the exercise from both sides: attacking the infrastructure, and reading what the detection layer actually caught. The gap between the two is where most of the learning sits.

HONEYPOTS · KIBANA · ELK · DETECTION
Mobile security

Deliberately vulnerable Android app

Built an Android application seeded with intentional flaws, designed as a training target for mobile penetration testing. Writing the vulnerabilities on purpose forces a precision that finding them never does: you have to know exactly why each one works.

ANDROID · KOTLIN · MOBILE PENTEST
Reporting

Network & system pentest report

Complete audit of a network and its systems, documented as a professional pentest report with findings, risk ratings and a mitigation strategy. A finding nobody acts on is a finding wasted, so the report was written for the person who has to fix it, not for the person who found it.

NETWORK · SYSTEMS · REPORTING · MITIGATION

Detailed write-ups are being published as I go. Read the blog or see the full profile.