JF / 2026
Available
CASE FILE 2026-JF-01 Valencia area · ES — GMT+1

Jonas Fernandez

Jonas Fernandez

Cybersecurity Associate & Vulnerability Researcher. I break software on purpose, then build the detections and defenses that stop the next person from doing the same.

Credentials

Cert
OSCP+
Cert
CRTO
Cert
eJPTv2
Training
Maldev · Malware in C
200+ Machines
compromised
70+ Pentest
reports
04 Vulnerabilities
disclosed
07 Certifications
& training
Journal

Latest research

All research
Builds

Recent projects

All projects
RESEARCH 2026

TombWatcher — Full AD Compromise via ADCS ESC15 and Tombstone Restoration

A complete penetration test report of a Windows Active Directory environment: WriteSPN for Kerberoasting, gMSA password extraction, WriteOwner abuse, ADCS ESC15 exploitation, and tombstone restoration to recover a deleted certificate admin account. From assumed-breach user to Domain Admin in a single chain.

Active DirectoryADCSKerberosBloodyADCertipyImpacketNetExecgMSADumperLDAP
RESEARCH 2026

VulnCicada — Full Active Directory Compromise via AD CS ESC8

A complete penetration test report of a Windows Active Directory environment: NFS unauthenticated export, plaintext credentials, Kerberos password spraying, PetitPotam coercion, NTLM relay to AD CS web enrollment, and DCSync. Four chained vulnerabilities leading to domain admin in under two hours.

NFSKerberosAD CSCertipyBloodyADImpacketNetExecPetitPotamESC8DCSync
RESEARCH 2026

CLAI — Autonomous Pentesting with LLM Agents

Using an open-source terminal-native AI agent to autonomously enumerate and exploit HackTheBox machines. An honest evaluation of what LLM agents can do with Nemotron 3 Ultra 550B, where they fail, and the prompt engineering that makes the difference between a stalled session and a root shell.

CLAINode.jsNVIDIA NIMNemotron 3 UltraLLM AgentsPentesting
RESEARCH 2026

Sliver C2 Stager — Staged Payload Delivery with AV/EDR Evasion

A complete staged payload pipeline: Sliver mTLS beacon, XOR-obfuscated URL in a custom C stager, PEB process path spoofing, Startup-folder persistence, and delivery wrapped inside a fake Chrome installer with a spoofed Authenticode signature.

CSliverMinGWCloudflaredOpenSSLWindows InternalsSysmonWazuh
Say hi

Open to opportunities
worth pursuing.

Get in touch See profile