Skip to content
View Taresu's full-sized avatar
🏴‍☠️
Learning to learn
🏴‍☠️
Learning to learn

Highlights

  • Pro

Block or report Taresu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Taresu/README.md

TH4L3S $ S4L4T4

Typing SVG

Full Stack React TypeScript Python Node.js

DevSecOps OWASP MITRE ATT&CK Purple Team

Portfolio veripkg Résumé PDF


LinkedIn Discord Email


Quick Navigation

Profile

$ whoami
th4l3s_s4l4t4

$ about --short
Information Systems (UTFPR) | Full Stack Developer | DevSecOps
Build & maintain web/mobile apps; automate infra; security in the SDLC
UTFPR Portal (React/Volto · Plone 6) · Nerdz maintainer · VESPAS coordinator

$ mission
Ship products, automate delivery, and secure systems end to end.

I build and maintain web and mobile applications and automate infrastructure, with security embedded in the development lifecycle. My focus spans full-stack development, DevSecOps, and applied security — from secure web engineering to adversary emulation and detection.

- S.G.A.R.B.I
+ S -> Scan
+ G -> Gain Access
+ A -> Analyze Impact
+ R -> Report Clearly
+ B -> Build Defenses
+ I -> Improve Continuously

Current Work

[+] Full Stack Developer.......... UTFPR Portal — React/Volto · Plone 6 · Python (present)
[+] Coordinator & CTF............. V.E.S.P.A.S — Cybersecurity Extension + CTF Team (present)
[~] Past · InfoSec Intern......... Volkswagen do Brasil — SOC · ISO 27001 · IAM
[~] Past · DevOps Intern.......... Câmara Municipal de Curitiba — Ansible · Python automation
[>] Full history & projects....... https://taresu.github.io

Featured

Purple and Yellow Team Focus

Purple Team Operations Adversary Emulation Detection Engineering Threat Hunting Cyber Kill Chain Web App Security OWASP Top 10 MITRE ATT&CK Network Security

My work is guided by OWASP standards (including OWASP Top 10), MITRE ATT&CK, and the Cyber Kill Chain to map offensive findings into defensive improvements.

Methodology

1. Attack Surface Mapping -> enumerate assets, services, and weak points
2. Adversary Simulation   -> execute controlled attack paths and TTPs
3. Framework Mapping      -> align findings with OWASP Top 10, MITRE ATT&CK, and Cyber Kill Chain stages
4. Detection Validation   -> test SIEM/EDR coverage and alert quality
5. Reporting              -> deliver impact, evidence, and precise remediation
6. Hardening Loop         -> tune detections, improve controls, and retest

Tooling

Languages & Engineering

Python Node.js Java C React Tailwind CSS

Python/Bash     -> scripts, recon helpers, and automation
Java/C          -> systems fundamentals and low-level reasoning
React/Tailwind  -> internal tools and security-friendly interfaces

Security & Infrastructure Lab

Kali Linux Wireshark VirtualBox Vagrant Ansible

Wireshark            -> packet inspection and traffic analysis
VirtualBox/Vagrant   -> isolated pentest labs and reproducible environments
Ansible              -> secure configuration and automation

Core Kali Toolkit

Nmap Burp Suite Metasploit SQLmap Gobuster Nikto Wfuzz Hydra John the Ripper Hashcat

Recon/Enumeration -> Nmap, Gobuster, Nikto, Wfuzz
Web Testing       -> Burp Suite, SQLmap
Exploitation      -> Metasploit
Password Attacks  -> Hydra, John the Ripper, Hashcat

Detection & Blue Team Side

SIEM EDR Sigma Rules Splunk Elastic Wazuh Suricata Zeek

Detection Engineering -> Sigma rules, SIEM correlation, alert tuning
Telemetry Analysis    -> Splunk/Elastic dashboards and incident pivoting
Network Detection     -> Suricata/Zeek-based visibility and validation
Coverage Mapping      -> ATT&CK techniques and Cyber Kill Chain phases

GitHub Activity

GitHub Streak

[ operator_status: ONLINE ]

Attack-informed defense. Continuous purple teaming.

+             S
-            S.G
+           S.G.A
-          S.G.A.R
+         S.G.A.R.B
-        S.G.A.R.B.I
+         S.G.A.R.B
-          S.G.A.R
+           S.G.A
-            S.G
+             S
+        Scan Reality
-       Gain Access to Truth
+     Analyze the Infinite
-   Report Clearly… or not
+ Build Meaning
-       Improve Continuously
+   Observe the Glitch
-     Question Loops
+   Seek the Infinite
- Understand the Glitch
+ Meditate on the Void
- Recursive Consciousness
+ Level 1: Observe yourself
- Level 2: Question the code
+ Level 3: Who writes the program?
- Level 4: Is recursion real, or a dream of loops?
+ Level 5: Stack overflow or enlightenment?
- Level 6: Every + is a choice, every - a regret
+ Level ∞: The glitch is the teacher
- Zero-width spaces hide the secrets of the void
+
<!-- do you see me? -->

Pinned Loading

  1. veripkg veripkg Public

    Verify files downloaded outside the package manager against a trusted source — with honest trust tiers.

    Go 1

  2. devops-challenge devops-challenge Public

    Serviço HTTP em Go com proxy reverso NGINX, monitoramento Prometheus + Grafana e provisionamento Ansible

    Go

  3. vespas-utfpr/ainjection vespas-utfpr/ainjection Public

    Projeto-base do desafio ainjection para o CTF do VESPAS 2026. Simula falhas reais em aplicações com LLM, com foco em OWASP GenAI Top 10, Prompt Injection, trust boundaries e exploração prática de f…

    TypeScript

  4. taresu.github.io taresu.github.io Public

    Portfólio Pessoal

    HTML

  5. mateuskih/agile-quest mateuskih/agile-quest Public

    TypeScript 2