$ whoami#

Hi Stranger! I am Soufiane Hachimi, known as ryuk0x01, an Offensive Security Researcher and Software Engineer based in Oujda, Morocco.

My pursuit is centered around a straightforward offensive doctrine: finding the friction points where application logic breaks under real-world attack vectors. Whether hunting authorization bypasses in multi-tenant SaaS platforms, dissecting API parser inconsistencies, or building custom security tooling in Go and Rust, I bridge the gap between understanding how systems work and making them fail securely.

I like to break things responsibly.


My Approach#

  • Web Security Research — Actively hunting for logic flaws, authorization bypasses, and API vulnerabilities across cloud-native architectures.
  • Low-Level & Tooling Engineering — Building performant custom scanners, CLI utilities, and automation frameworks in Go, Rust, and Python.
  • CTFs & Wargames — Competing in advanced exploitation challenges across HackTheBox and CTF competitions to sharpen real-world attack techniques.

Intigriti LeakyJar CTF Challenge

  • Exploited SameSite=None boundaries on a document-sharing endpoint to forge privileged API requests and exfiltrate secret vaults.

Hack The Box — Dante Pro Lab (27/27 Flags)

  • Executed full Active Directory compromise, internal network pivoting, NetExec exploitation, and multi-node privilege escalation.

Vulnerability Research & Logic Flaws

  • Discovered authorization bypass chains, IDORs, and API parser inconsistencies across multi-tenant SaaS environments.

Technical Arsenal#

  • Offensive Security: Burp Suite Pro, Logic Flaw Testing, BloodHound, NetExec, Nmap, API Security Auditing.
  • Languages: Go, Rust, Python 3, JavaScript / TypeScript, POSIX C, Java (Spring Boot).
  • Systems & Infra: Linux Systems, Docker, Custom Shell Utilities, Wireshark, RESTful APIs.

Operator Timeline#

  • Zone01 Oujda (2024 — Present) — Computer Science & Software Engineering Specialization.
  • Independent Security Research (2023 — Present) — Bug bounty hunting, CTFs, and offensive tooling development.

Let’s Connect#

I am constantly seeking challenging security engineering roles, bug bounty collaborations, and offensive research opportunities.