JF / 2026
Available
CASE FILE 2026-JF-01 Valencia area · ES — GMT+1

Jonas Fernandez

Jonas Fernandez

Cybersecurity Associate & Vulnerability Researcher. I break software on purpose, then build the detections and defenses that stop the next person from doing the same.

Credentials

Cert
OSCP+
Cert
CRTO
Cert
eJPTv2
Training
Maldev · Malware in C
200+ Machines
compromised
70+ Pentest
reports
04 Vulnerabilities
disclosed
07 Certifications
& training
Journal

Latest research

All research
Builds

Recent projects

All projects
RESEARCH 2026

VulnCicada — Full Active Directory Compromise via AD CS ESC8

A complete penetration test report of a Windows Active Directory environment: NFS unauthenticated export, plaintext credentials, Kerberos password spraying, PetitPotam coercion, NTLM relay to AD CS web enrollment, and DCSync. Four chained vulnerabilities leading to domain admin in under two hours.

NFSKerberosAD CSCertipyBloodyADImpacketNetExecPetitPotamESC8DCSync
RESEARCH 2026

CLAI — Autonomous Pentesting with LLM Agents

Using an open-source terminal-native AI agent to autonomously enumerate and exploit HackTheBox machines. An honest evaluation of what LLM agents can do with Nemotron 3 Ultra 550B, where they fail, and the prompt engineering that makes the difference between a stalled session and a root shell.

CLAINode.jsNVIDIA NIMNemotron 3 UltraLLM AgentsPentesting
RESEARCH 2026

Sliver C2 Stager — Staged Payload Delivery with AV/EDR Evasion

A complete staged payload pipeline: Sliver mTLS beacon, XOR-obfuscated URL in a custom C stager, PEB process path spoofing, Startup-folder persistence, and delivery wrapped inside a fake Chrome installer with a spoofed Authenticode signature.

CSliverMinGWCloudflaredOpenSSLWindows InternalsSysmonWazuh
PUBLIC 2026

Under 60 Seconds — Browser Credential Theft via USB

A .bat script that weaponizes an unlocked workstation and a USB port — disables Defender, dumps browser credentials with SharpChromium, restores Defender, gone in under a minute. A study of what physical access actually buys an attacker.

BatchC#WindowsPhysical AccessDPAPI
Say hi

Open to opportunities
worth pursuing.

Get in touch See profile