Hi, I'm Kitsu

Ethical hacker and penetration tester from Russia, specializing in bug bounties, red teaming, and network penetration testing. Enthusiast of website exploiting, front-end development, scripting, and currently diving into malware development

View Achievements
kitsu@home $whoami a cute little fox
⣿⣿⣿⣿⣿⡿⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⠇⠀⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⡟⢠⣧⠈⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⡏⢠⣿⣿⣷⣄⠈⠛⠛⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⠟⢠⣿⣿⣿⣿⣿⣷⡄⢀⠈⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⠏⢠⣿⣿⣿⣿⣿⣿⣿⣿⣄⣇⠈⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⡏⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡆⠸⣿⠟⠻⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠿⠿⣿⣿⣿⣿⣿⣿⣿ ⠁⢾⡿⠟⣋⣭⣍⠛⠟⣉⣴⣌⠛⠇⠀⠏⠀⠀⠀⠈⠻⣿⣿⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠀⢻⣿⣿⣿⣿⣿⣿⣿ ⠀⣠⣶⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⠂⣰⠀⢀⡀⠀⠀⠀⠈⠻⣿⣿⣿⣿⡟⠁⠀⠀⠀⣴⡆⢸⣿⣿⣿⣿⣿⣿⣿ ⡆⢹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⢠⣿⠀⣾⣿⣦⠀⢤⣤⡀⢉⣉⣉⣉⠀⠻⠿⠏⣼⣿⡇⢸⣿⣿⣿⣿⣿⣿ ⣷⡈⢿⣿⣿⣿⣿⣿⣿⣿⣿⡏⢀⣾⣿⠀⣿⣿⣿⣷⡈⢿⣧⣤⣿⣿⣿⣿⣷⣶⣌⠻⣿⡇⢸⣿⣿⣿⣿⣿⣿ ⣿⣷⡀⠙⢿⣿⣿⣿⣿⣿⡿⠀⠸⠿⣿⡄⣿⣿⣿⣿⡏⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣌⠁⣼⣿⠛⠛⠻⣿⣿ ⣿⣿⣿⣶⣄⡉⠻⠟⠋⣡⣤⣶⣶⣦⣄⡁⠸⣿⡿⠏⣰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⢻⣿⠀⡖⢀⠀⢹ ⣿⣿⣿⣿⠟⠋⣠⣶⣿⣿⣿⣿⣿⣿⣿⣿⡆⢈⣡⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⠀⠠⠊⢀⣾ ⣿⡿⠟⢁⣴⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠸⣿⣿⣿⠋⠀⣿⣿⣿⣿⣿⣿⡟⠉⣿⣿⠇⢸⣿⣦⣴⣾⣿⣿ ⡇⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⠀⠻⠷⠿⠦⠾⣿⣿⠉⠁⢉⣿⣄⣀⣿⡟⠀⠾⢿⣿⣿⣿⣿⣿ ⣷⣤⣄⣀⣉⣉⣉⢛⠛⠛⠛⠻⠿⠛⠿⠟⠛⠿⠿⠆⠀⠀⠀⠀⠛⠂⠀⠋⠉⠉⢙⡃⠀⠀⠀⠀⣸⣿⣿⣿⣿⣿

Skills

Bug-bounty Hunting

Finding vulnerabilities inside web-servers and network firmware. Since this is only a side-hobby, I have not developed it further however I am planning to set a goal of reaching $10,000 by the end of the year.

Web Exploitation

Doing CTFs and pwning machines competitively is a pretty big hobby of mine, which I am currently active in.

Network penetration testing

Attack strategies for network infrastructure, including firewall/IDS bypass, traffic analysis and interception. Experienced in wireless network penetration and exploiting network services.

Programming/Automation

4+ years of using python for penetration testing including working with multiple libraries, primarily scapy and flask. Also front-end development, and learning C for malware development.

Firmware/MCU Development

Working and creating DIY projects to test surroundings on a more external level such as working with raspberry-pi microcontrollers and ESP boards.

Achievements

Bug Bounty Earnings

Identifying (mostly) network exploits and firmware vulnerabilities, along with some lower-severity web issues—brought in around $3,940 through bug bounties. Not much continuation as this is more of a side-hobby alongside actual work.

Anti-malware web crawling architect

Developed multiple automated web-crawlers that identifies and deletes or automates reporting of remote communication tunnels and services, mostly web-hooks. it has removed 4562 web-hooks. Read my article on medium

Mentoring and Education

After 5 years of experience, starting to make environments and resources for beginners to learn cybersecurity. Most recently being youtube channel, as well as tools to teach beginners reconnaisance: nmap-kitty. Also planning on making write-ups for projects and more extensive guides in the future.

Projects

Work in Progress: nightshell

Malware-Development Operational Security

A completely untraceable RAT, routed through the tor network, with no interaction with exit nodes. Made to become resilient and untraceable from goverment units including the FBI, CIA and other. Includes end-to-end encryption to avoid compromised nodes, and encrypted file transfer.

Work in progress - Limited access due to ethics and legal reasons.

URL-Mirror

Anonymization Containerization Anti-Phishing

URL-mirror is a free service that sandboxes web pages, allowing users to safely view potentially malicious or phishing links without risk. It also helps bypass censorship, providing access to unbiased news in restricted regions by routing the content through an American proxy.

Visit website

nekolyze

Malware Analysis Incident Response

another WIP project that offers YARA based file scanning, trained on over 15,000 rules, providing quick and precise detection of algorithms within files, detecting goverment-used viruses, as well as other types of malware.

Visit website

nmap-kitty

Reconnaissance Website/Networks Cheat-Sheet

A simple quality of life tool to craft nmap commands with ease, Includes every argument which you can select with a single click to then copy the command to run. A very useful tool for beginners to learn the arguments, and for experts to use as a quality of life tool.

Visit website

kitsu-picoscripts

MCU modifications BadUSB Penetration Testing

A simple python compatibility layer for the CircuitPython firmware, to allow easy payload scripting and HID spoofing. With support for both US and UK keymapping.

View code

Contacts

You can view more projects, interact with my community, or donate using the buttons below: