Skip to content
View ssstrickys's full-sized avatar

Highlights

  • Pro

Block or report ssstrickys

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ssstrickys/README.md

Intercepted transmission banner: classified operator dossier for ssstrickys

Animated terminal decrypting the operator file line by line


Profile views counter for ssstrickys   Status: active, red team   Posture: authorized engagements only

╔════════════════════════════════════════════════════════════════════════════╗
║  //BEGIN TRANSMISSION                                   REF // SSS-0xCODY  ║
╠════════════════════════════════════════════════════════════════════════════╣
║                                                                            ║
║   OPERATOR ......... Cody Richard                                          ║
║   CALLSIGN ......... ssstrickys                                            ║
║   ROLE ............. Offensive Security Operator · Red Team                ║
║   FOCUS ............ Recon · Exploit Tooling · Active Directory            ║
║   DAILY DRIVER ..... Kali Linux · terminal-native · Python (uv) + Bash     ║
║   POSTURE .......... Authorized engagements only · every action logged     ║
║   DISPOSITION ...... Ships bold. Builds in the dark. Releases in the open. ║
║                                                                            ║
╚════════════════════════════════════════════════════════════════════════════╝

//WHOAMI  —  SUBJECT ASSESSMENT

Offensive-security operator who lives in the terminal — Kali on the daily driver, nmap and BloodHound on the wire, HackTheBox and CTF rigs for reps, Python (uv toolchain) and bash for everything in between. I build my own tooling: when the thing I need doesn't exist, I write it.

Operating doctrine: if the tooling doesn't exist, write it; if it's risky, gate it; if it acts, log it.

[ RECON ]  ·  [ EXPLOIT TOOLING ]  ·  [ ACTIVE DIRECTORY ]  ·  [ LINUX INTERNALS ]  ·  [ TOOLING DEV ]


//ARSENAL  —  FIELD-ISSUED TOOLING

OPERATING THEATER

Kali Linux Linux internals GNU Bash GNU shell and CLI

OFFENSE // RED TEAM

HackTheBox Nmap reconnaissance BloodHound on Neo4j for Active Directory CTF and exploit tooling

BUILD // ENGINEERING

Python uv toolchain Git GNU/Linux

//DISCLOSURES  —  COORDINATED VULNERABILITY DISCLOSURE

Five GitHub Security Advisories published   Disclosure coordinated and fixed

Vulnerabilities reported under published disclosure programs, coordinated with maintainers, and tracked to fix. Full write-ups → ssstrickys.com/research

Target: koala73/worldmonitor  ·  Tauri 2 / Rust / TypeScript  ·  real-time global intelligence platform

Severity CVSS Advisory Class
🔴 High 8.8 GHSA-2x6r-qq54-mmhr CWE-78 · Windows command injection (Tauri open_url IPC)
🔴 High 7.5 GHSA-r649-4cqj-w93h CWE-306/639 · Unauthenticated cross-tenant read (BOLA)
🟠 Moderate 5.3 GHSA-c267-988w-7pq7 CWE-290/807 · Rate-limit bypass via spoofable IP header
🟠 Moderate 4.3 GHSA-hcq5-jm84-2395 CWE-770 · MCP daily cost-cap bypass
⚪ Low 2.7 GHSA-f6gj-3v7v-j75q CWE-613 · OAuth refresh-token reuse without family revocation

Also credited in the project's Security Acknowledgments and PR #1103 (cache-key hardening).


//SIGNAL INTELLIGENCE  —  OPERATIONAL TELEMETRY

GitHub statistics card for ssstrickys Contribution streak card for ssstrickys


Most-used programming languages for ssstrickys


//ACTIVITY TRACE  —  INTERCEPTED CONTRIBUTION SIGNAL

Contribution activity graph for ssstrickys


Animated contribution snake traversing the contribution grid for ssstrickys


//ENGAGEMENT RULES — operates only under written authorization. all actions logged.

End of transmission footer banner

Popular repositories Loading

  1. ssstrickys ssstrickys Public

    ✦ ssstrickys — offensive security & red team. (GitHub profile.)

  2. worldmonitor worldmonitor Public

    Forked from koala73/worldmonitor

    Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface

    TypeScript