Skip to content
View nicolasferrerm's full-sized avatar

Block or report nicolasferrerm

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nicolasferrerm/README.md

Nicolas Ferrer

Advanced Cybersecurity Specialist | Offensive Security & Architecture

LinkedIn Medium

About Me

I am a Cybersecurity Specialist focused on securing modern infrastructure and web applications. My approach goes beyond traditional vulnerability scanning; I specialize in uncovering complex business logic flaws, API vulnerabilities, and architectural misconfigurations. I bridge the gap between offensive testing and engineering mitigation.

Currently based in/targeting the Canadian tech market, with a focus on delivering actionable security intelligence for enterprise environments.

Core Focus Areas

  • Offensive Security: Advanced Web & API Exploitation, Logic Flaws (BOLA/IDOR), Identity & Access Management vulnerabilities (OAuth/JWT).
    • Security Engineering: Threat Modeling, Secure Architecture Review, Mitigation Strategies for Modern Stacks (Cloud, Next.js, APIs).
      • Tooling & Automation: Developing specialized Python-based tooling to automate complex security testing workflows that standard scanners miss.

      • Featured Security Tooling

        • API Logic Security Fuzzer (En Desarrollo) - A Python-based framework designed to automate the discovery of Broken Object Level Authorization (BOLA) vulnerabilities in REST APIs by managing and cross-referencing multiple JWT sessions.

        • Recent Security Research

          • [Medium] Upcoming: The Architecture of API Logic Flaws - Moving Beyond Injection

          • Tech Stack & Proficiencies

            • Security: Burp Suite Professional, Owasp ZAP, Postman, Custom Python Tooling.
              • Languages: Python (Security Automation), Bash, Go (Familiar).

                • Concepts: OWASP Top 10, API Security, Cloud Security Posture, Identity Management.

                "Security is not just about breaking things; it's about understanding complex systems better than the people who built them, and helping them build resilience."

Popular repositories Loading

  1. BOLA-Strike-Enterprise BOLA-Strike-Enterprise Public

    Autonomous API Warfare & DevSecOps Orchestration Platform — AI-driven BOLA/IDOR vulnerability detection with MITRE ATT&CK mapping, CVSS v4.0 scoring, and FAIR financial telemetry

    Python 1

  2. nicolasferrerm nicolasferrerm Public