Breaking || securing things for fun and profit

HTB Certified Penetration Testing Specialist (CPTS)

Veteran turned cybersecurity professional. HTB CPTS certified.

Working across the offensive-defensive spectrum: penetration testing, incident response, SOC engineering, and Active Directory hardening.

I build security tooling - MCP integrations for pentest reporting, DFIR automation scripts, SOC orchestration pipelines, and infrastructure-as-code for secure environments. Most of this work lives in private repositories.

On the open-source side, I'm a contributor to Spacedrive (38k+ stars), landing merged features and fixes in the Rust core and TypeScript client, and I maintain reptor-mcp, an MCP server for SysReptor pentest reports.

I also build developer tooling around AI agents and LLM integrations, bridging the gap between security operations and modern agentic workflows.

Projects

Products, platforms, and prototypes.

reptor-mcp

MCP server that turns the reptor CLI into a programmable service for SysReptor pentest reporting, so AI agents and scripts can drive report automation over the Model Context Protocol. Dynamically wraps reptor's plugins (nmap, nessus, burp, zap, sslyze, openvas, qualys and more) as MCP tools, and adds direct-API tools for findings CRUD, schema discovery and template management. Built on FastMCP 3 in Python with async-safe, thread-serialized plugin execution and configurable field exclusion to strip sensitive data before it reaches an LLM.

MIT-licensed, v0.2.0; built on FastMCP 3 / reptor 0.34

Active

PythonMCPFastMCPSysReptorPentestAI AgentsSecurity Tooling

Ouitransfer

Self-hosted, open-source file transfer platform. Upload files and share them via links with password protection, expiration dates and view limits; reverse shares let others send files back to you. Built as a pnpm/Turborepo monorepo — Fastify 5, Prisma and SQLite on the backend, Next.js 15 / React 19 / Tailwind 4 on the front. Ships built-in RustFS for zero-config S3-compatible storage (or connect any S3 provider), plus LDAP/Active Directory sync, OIDC/SSO, TOTP 2FA, multi-user roles and quotas, configurable email notifications, and full i18n across 23 languages including RTL. Deploys via Docker Compose in three containers.

Beta · self-hostable

TypeScriptNext.jsFastifyPrismaDockerS3Self-hostedOIDCLDAP

Spacedrive Contributions

Merged contributor to Spacedrive, the open-source cross-platform file manager powered by a virtual distributed filesystem written in Rust (38k+ stars). Landed features and fixes across both the Rust core and the TypeScript client, merged alongside founder Jamie Pine — including a tag system with explorer integration and media context-menu fixes (#3054), a fix for a sync protocol busy-loop (#3057), and a fix preventing an Overview crash from single-resource cache seeding in the TS client (#3055).

38k+ stars; merged PRs in the Rust core and TypeScript client (#3054, #3055, #3057)

Active contributor

RustTypeScriptOpen SourceDistributed SystemsFile Systems

Proof

Milestones, rankings, and results.

Skills

The work slvn is useful for.

Penetration Testing
Active Directory Security
Incident Response & DFIR
SOC Engineering
Python
TypeScript
PowerShell
Rust
Infrastructure as Code
MCP & AI Agent Tooling
SurrealDB

Work with slvn

Selected advisory and build work.

Open Source Collaboration

Collaboration

FlexibleRemote

Open to collaborating on security tooling, MCP integrations, and open-source projects in the cybersecurity and developer tools space. Not looking for employment - interested in interesting problems and meaningful contributions.

Free

Security Advisory & Consulting

Advisory

FlexibleRemote

Advisory across the offensive-defensive spectrum: penetration test scoping and program design, SOC engineering and detection strategy, incident response readiness, and Active Directory hardening. Also advise teams building security tooling around AI agents and MCP/LLM integrations. HTB CPTS certified; veteran turned cybersecurity lead.

Custom

Contract Penetration Testing & Security Engineering

Contract

FlexibleRemote

Hands-on contract work: penetration testing, Active Directory assessment and hardening, incident response and DFIR, SOC orchestration pipelines, and infrastructure-as-code for secure environments. Comfortable building custom tooling — DFIR automation, pentest-reporting MCP integrations, and SOC automation — to fit the engagement.

Custom

Experience

Roles slvn has held.

Cybersecurity Lead · Industrial Group

Jan 2025 – Present

Lead security across an industrial group (employer anonymised for operational security). Work spans the offensive-defensive spectrum: penetration testing, incident response, SOC engineering, and Active Directory hardening, plus building internal security tooling and infrastructure-as-code for secure environments.

Team Leader — Operational Deployments · Military (service branch undisclosed)

Sep 2011 – Jan 2022

Ten years of service, deployed and leading a team on operations worldwide. Specifics withheld for operational security. The foundation for everything that came after: operating under pressure, leadership, and disciplined execution.

Education

Education.

ESD Academy

Sep 2023 – Jul 2025

Master Expert Securite Digitale

Advanced cybersecurity program covering offensive security, digital forensics, and security architecture.