Technical article
Alejandro Lopez Aguilar
Offensive Security Engineer, Pentester and Offensive Security Analyst at Hispasec. Software Engineer certified in OSCP+, OSCP, HTB CPTS and CWP, with professional experience conducting Black Box and Grey Box assessments of web applications, APIs, infrastructure and exposed services. Technical profile focused on controlled vulnerability validation and exploitation, proof-of-concept development, retesting and remediation-focused reporting.
Specialization
Red Teaming & Offensive Pentesting
Compromise of corporate environments through realistic attacks: web exploitation, pivoting across segmented networks, Active
Directory exploitation, post-exploitation and privilege escalation on Windows/Linux.
Malware Development
Development of offensive tools in C/C++ with Win32 API, process injection, hooking, AV/EDR evasion and Windows Internals
research.
Security Automation
Custom Python, PowerShell and Bash scripts to accelerate enumeration, exploitation, flag validation and technical documentation.
Featured Achievements
~ OSCP+ Certified with perfect score (100/100) - February 2026 ~ CWP Certified - Wireless network auditing and security ~ HTB CPTS - Professional pentesting methodology - 2025 ~ CTF-Lab Local - Corporate network pentesting lab designed as final degree project
Technical Stack
Offensive Security
Active Directory: Kerberoasting, AS-REP Roasting, DCSync, Zerologon, Golden/Silver Tickets, Constrained/Unconstrained
Delegation, NTLM Relay
Post-Exploitation: Mimikatz, Rubeus, PowerView, Empire C2, Cobalt Strike (Labs), BloodHound, SharpHound
Pivoting: Ligolo-ng, Chisel, SSH Tunneling, Port Forwarding, Socks Proxies
Evasion: AV/EDR bypass, AMSI bypass, Process Injection, API Unhooking
Development & Malware
Languages: C/C++ (Win32 API), C# (.NET), Python, PowerShell, Bash
Maldev Techniques: Process Injection (DLL, Shellcode), Process Hollowing, API Hooking, Reflective Loading, PE Injection, Thread
Hijacking
Advanced Evasion: Obfuscation, Packing (UPX, custom), Anti-Debugging, Sandbox Detection, AMSI/ETW Patching
Reverse Engineering: Ghidra, x64dbg, IDA (basic)
Pentesting & Tools
Web: OWASP Top 10, SQLi, XSS, SSRF, IDOR, Authentication Bypass, Burp Suite Pro, Caido
Network: Nmap, Masscan, Netcat, Wireshark, tcpdump
Password Attacks: John the Ripper, Hashcat, Hydra, CrackMapExec, NetExec
Enumeration: Ffuf, Gobuster, enum4linux-ng, ldapsearch, rpcclient
Exploitation: Metasploit, Exploit-DB, Custom Exploit Development
Sections
~ Certifications ~ Custom tools
Education
Software Engineering Degree | 2023 - 2026
Universitat Oberta de Catalunya (UOC)
Software Engineering track
Final Degree Project: CTF-Lab Local - Corporate network simulation for pentesting
Master's Degree in Cybersecurity | 2023 - 2024
CPIFP Alan Turing, Malaga
Ethical Hacking, Digital Forensics, Network Hardening, Compliance and Security Regulations
Higher Technician in Cross-Platform Application Development | 2021 - 2023
Colegio San Jose, Malaga
Java, Databases, Operating Systems, Web Development
Featured Projects
CTF-Lab Local | Final Degree Project
September 2025 - January 2026 | Grade: 9/10
Professional Experience
Pentester / Offensive Security Analyst | Hispasec | February 2026 - Present
~ Black Box and Grey Box assessments of web applications, APIs, infrastructure and exposed services ~ Controlled vulnerability identification, validation and exploitation ~ Proof-of-concept development, impact assessment, retesting and technical recommendations ~ External attack surface analysis covering exposed assets, domains, subdomains and associated risks
Cybersecurity Technician Intern | Grupo TOPdigital | June 2024 - July 2024
~ Security monitoring, vulnerability analysis and web application security reviews ~ Review of configurations, security policies and system hardening measures ~ Technical documentation and results reporting
Web Developer Intern | TYM | March 2023 - June 2023
~ Web feature development and maintenance using TypeScript and Angular ~ Git-based collaborative development workflows