Skip to content

About

Hello, I’m 0xJB 👾

I’m a Penetration Tester and Red Team Operator, and Founder of AetherGuard Technologies. I work across the full offensive security stack, from web applications down to firmware, turning offensive research into practical, defensible security improvements for the people I work with.

What I Do

Penetration Testing & Red Teaming

  • Internal network & Active Directory: enumeration, privilege escalation, lateral movement, Kerberos abuse (Kerberoasting, AS-REP roasting), credential attacks, and full attack-path mapping from foothold to domain compromise
  • Web application security: OWASP Top 10 testing, authentication/authorization bypass, business logic flaws, and API abuse
  • External and perimeter testing: exposed service enumeration and exploitation, including misconfigured or unauthenticated database and infrastructure services
  • Adversary simulation: building and operating C2 infrastructure, payload delivery, and detection/evasion research

Exploit & Malware Development

  • Exploit development in C/C++ and Python, from proof-of-concept to fully working exploits for authorized engagements
  • Malware development for red team tradecraft: custom implants, loaders, and encrypted/covert C2 communication channels
  • Reverse engineering: static and dynamic analysis of binaries and malware samples, unpacking, and behavioral analysis

Wireless, RF & Hardware Hacking

  • WiFi security: rogue AP attacks, Evil Twin/Evil Portal phishing, and WPA handshake capture and cracking
  • RF and radio hacking: 2.4GHz wireless peripheral attacks, SDR-based signal capture and analysis
  • Hardware and embedded device security

Development

  • Build most of my own tooling in Python and Go
  • Solid grounding in C/C++ for low-level and offensive tooling work

Homelab & Infrastructure

I run and maintain my own homelab as a testbed for the things I write about here:

  • Virtualization: a Dell PowerEdge R630 running Proxmox VE hosting the rest of the environment
  • Network segmentation: pfSense as the core firewall/router, with VLANs separating trusted, lab, and DMZ-style segments
  • Remote access: OpenVPN for site-to-site and remote connectivity between the lab and external infrastructure
  • Active Directory: a full AD domain for practicing enumeration, privilege escalation, and attack-path techniques against a real (if small) enterprise-style environment
  • Detection & monitoring: Wazuh for host-based intrusion detection and SIEM-style log aggregation across the lab
  • Hardening: nftables and fail2ban across exposed services, least-privilege SSH access scoped to internal network ranges only

Running both sides (attacker and defender) on infrastructure I own is what keeps the offensive work grounded in something realistic.

Bug Bounty & Research

Active in bug bounty hunting and independent security research, with a focus on network services, wireless attack surfaces, and application-layer vulnerabilities. Some of that research ends up written up in the Red Team Handbook and Writeups sections of this site.

Let’s Connect

Feel free to reach out if you’re interested in collaborating, discussing security trends, or just want to talk shop. Find me on GitHub, LinkedIn, or by email at jbernal@aetherguard.xyz.

“The best way to predict the future is to invent it.” (Alan Kay)