daniel@security: ~

$ whoami

daniel_fernandez ▊

$ cat mission.txt

15 years in IT operations. Now breaking things
ethically — penetration testing, security labs,
and the road to CEH.

$ ▊

Daniel Fernandez

Cybersecurity · Penetration Testing · Bug Bounties

Davie, FL · Remote

Lab Writeups Résumé (PDF)

# About

I'm an IT professional with 15 years across managed services and healthcare IT — most recently as a Level II Service Management Specialist on a 24/7 service desk — now pivoting into offensive security.

The pivot is deliberate: years of triaging incidents, flagging anomalies across 800,000+ records, and responding to a system-wide outage taught me how defenders think. Now I'm learning to think like an attacker — legally, in labs, and under authorization only — through hands-on penetration testing practice, security coursework, and the road to the CEH certification.

15years in IT
7certifications earned
1certs in progress

# Certifications & Training

Earned

  • ✓ CompTIA A+
  • ✓ CompTIA Network+
  • ✓ CompTIA IT Operations Specialist (CIOS)
  • ✓ ITIL 4 Foundation
  • ✓ OPSWAT Certified File Security Associate (OCFA)
  • ✓ Google Cybersecurity Professional
  • ✓ B.S., Data Management / Data Analytics — WGU

In Progress

  • … Certified Ethical Hacker (CEH) — EC-Council
  • … TryHackMe & HackTheBox — active lab work

# Methodology & Tools

How I approach a test — practiced in labs, applied with discipline.

  1. Reconnaissance — passive footprinting, DNS enumeration, service discovery
  2. Scanning & Enumeration — Nmap, service versioning, share and user enumeration
  3. Vulnerability Analysis — mapping findings to exposures, manual verification
  4. Exploitation — fundamentals in lab environments, privilege escalation basics
  5. Reporting — structured findings with severity, evidence, and remediation guidance
Kali Linux lab Nmap lab Burp Suite learning Wireshark lab Metasploit lab Linux proficient Python proficient Active Directory 6 yrs Networking Net+

Tool labels are honest: lab = hands-on in practice environments (TryHackMe / HackTheBox); learning = currently studying.

# Lab Writeups

Notes from the lab. Retired machines only — no live spoilers, ever.

📟 Kali Linux CLI Cheat Sheet

My complete command reference, organized by engagement phase — daily driver, recon & enumeration, exploitation, post-exploitation, wireless. Built from scratch and verified.

resource

🧪 TryHackMe Room Writeups

In progress — writeups land here as I complete rooms. Methodology notes, dead ends included: the failures teach more than the flags.

coming soon

# Bug Bounty

Currently in the training phase: methodology first, programs second. HackerOne and Bugcrowd profiles go live here once I'm submitting.

Scope discipline is non-negotiable — authorized targets only, full report quality on every submission.

in training

# Home Lab

  • Attack platform: Kali Linux — persistent encrypted USB (Ventoy multiboot) plus VM
  • Practice ranges: TryHackMe and HackTheBox labs
  • Target VMs: intentionally vulnerable machines for offline practice
  • Supporting stack: Parrot OS, Wireshark, Python scripting environment

Everything here runs against lab targets I own or am authorized to test. That boundary is the whole point of the craft.

# Data Background

The analyst foundation underneath the security work — kept, reframed.

📊 Anomaly Detection at Scale

QA review methodology across 800,000+ records — flagging outliers for investigation. The same muscle behind identifying anomalous network behavior.

🧪 Experimental Discipline

A/B testing and structured analysis background — hypothesis, control, evidence. Directly transferable to methodical penetration test execution.

More on GitHub →

# Contact