Security engineering, reverse engineering, backend systems, DevSecOps, and practical AI-assisted tooling.
Building security and developer tools that stay useful when the lab gets noisy.
Made with 🖤 in Barcelona City 🇪🇸
I build and document security tooling across reverse engineering, malware analysis, Linux workstations, backend systems, and DevSecOps automation.
The public work here is intentionally bounded: defensive research workflows, authorized lab environments, developer tooling, automation, packaging, and educational software. Some older repositories are left public as historical proof-of-concepts, but they are not the front line of the profile.
Current focus:
- malware-analysis and reverse-engineering workflows
- OSCP preparation through structured Hack The Box practice
- defensive Arch/AUR incident response tooling
- Linux desktop and packaging automation
- backend services, security APIs, and DevSecOps glue
- local-first AI workflows for engineering work
- small apps that solve real problems for real people
| Project | Signal |
|---|---|
| GhostTrace Lab | Malware-analysis and reverse-engineering lab focused on safe, documented security research workflows. |
| AUR Incident Defense Kit | Defensive Arch/AUR audit kit for package correlation, pacman timelines, IOC checks, and remediation planning. |
| Codex UI Linux Port | Unofficial Linux packages and release automation for Codex UI across Arch/CachyOS, Debian/Ubuntu, and RPM builds. |
| token-rat-esp | Spanish Codex skill for shorter answers, cleaner patches, and token-efficient developer workflows. |
| Mente Activa | Educational Godot app with accessible short memory, language, and attention activities for older adults and caregivers. |
| paginaSantuarioDana | Volunteer web work supporting Santuario Dana Tagoro after the Valencia DANA disaster. |
I keep security work framed around authorization, reproducibility, and defensive value.
- I am using Hack The Box as a public OSCP-preparation practice track, starting with Starting Point and moving toward retired machines and lab-style repetition.
- GhostTrace Lab ties static analysis, local AI reasoning, triage state, and sandbox evidence into one research workflow.
- AUR Incident Defense Kit focuses on local package incident review for Arch-based systems.
- LAN Enumeration and Reconnaissance Tool is kept in the authorized network visibility lane.
- Tor AttackTools Lab belongs in controlled lab and education contexts.
Older proof-of-concept repositories such as GoKeylogger, Remote-Admin-Tool, and PythonCrypter are part of the historical trail, not the profile's main signal.
I like tools that reduce operational drag:
- Codex UI Linux Port for Linux packaging around a real workstation workflow.
- token-rat-esp for compact coding-agent output in Spanish.
- Mente Activa for accessible educational activities built in Godot.
- warpdesk for a native Linux frontend around Cloudflare WARP workflows.
- terraform-aws-samples for infrastructure-as-code samples.
Security and systems:
- reverse engineering, malware analysis, DFIR-oriented workflows
- Linux, Windows, Docker, PowerShell, Bash
- Python, Go, shell tooling, backend services
- CI/CD, packaging, incident review, automation
AI and product tooling:
- local-first AI workflows
- coding-agent ergonomics
- retrieval and memory experiments
- practical assistants tied to real tools
Former global moderator of two historic Spanish-speaking security communities:
- Cuadernos de Hack x Crack — the old material that first pulled me toward computing and hacking.
- Hack x Crack archive
- Underc0de profile
That background still shapes how I evaluate tools: useful beats decorative, evidence beats noise, and public work should be clear about its boundary.
- GitHub: github.com/0xCyberBerserker
- LinkedIn: linkedin.com/in/jcarlosgl-offensive-security

