// OPERATIVE DOSSIER //
ESTEBAN JIMENEZ
RED TEAM OPERATOR // BLUE TEAM & SOC // PURPLE TEAM STRATEGIST
Offensive security researcher focused on Red Team operations, API security, and Active Directory exploitation. Currently Red Team Intern at Telefónica Ecuador (Otecel S.A.): authorized pentests, API security testing, and CIS Benchmark audits. Ranked #1 in Ecuador and Top 50 worldwide on Hack The Box (peak #36, Grandmaster rank, Lvl 91), with all 6 Pro Labs and every Fortress completed. Captain of CyberFlippers and UDLA-Cyber.
Global Mastery & Recognition
Hack The Box
Hands-on pentesting platform and enterprise lab environment.
Holmes CTF 2025
Hack The Box's first defensive CTF. All 65 flags captured (100%) across Threat Intel, SOC, DFIR, malware reversing, and memory analysis.
LACC — Digital Forensics
Pre-selected in the Digital Forensics category of the Latin American Cybersecurity Challenge, under the CyberFlippers national team.
CyberFlippers Captain
Competitive team focused on international CTFs and technical training.
Professional Trajectory
Red Team Intern
Telefónica Ecuador · Otecel S.A.Orchestrate authorized offensive assessments across corporate infrastructure: CIS Benchmark audits, API security testing, and Docker image certification in production. Every finding directly reduces the attack surface.
CTF Player & Captain
Hack The Box · CyberFlippers · UDLA-CyberLead Ecuador's competitive scene as #1 nationally and Top 50 worldwide (peak #36), Grandmaster rank (Lvl 91). Completed all 6 Fortresses and multiple Pro Labs — Reversing, Forensics, and Pwn. Captain of CyberFlippers (national team) and UDLA-Cyber. Pre-selected for LACC in Digital Forensics.
Teaching Assistant · Cybersecurity
Universidad de Las Américas (UDLA)Train the next generation of security operators. Design and supervise exploitation and defense labs, bringing real-world offensive tactics into the classroom.
Bug Hunter
HackerOneExecute coordinated disclosure of critical web vulnerabilities: XSS, CORS misconfigurations, SSRF, and injections. Manual analysis with Burp Suite against OWASP Top 10 vectors, prioritizing technical impact over report volume.
Cybersecurity Engineering
Universidad de Las Américas (UDLA)Academic foundation in Cybersecurity Engineering — systems exploitation, hardening, and forensic analysis. Graduating 2027.
Competency Matrix
Offensive Operations
Tooling & Languages
Blue Team & DFIR
Authored Projects
Flipper CyberAttack Suite Flagship
PowerShell · HardwareAutomates the full physical-access assessment cycle: payload deployment, BadUSB emulation, and controlled RF attacks from a single Flipper Zero. Built for red-team ops where dwell time in the field matters.
View sourceAPI Security Testing Suite
Python · API Security264 offensive test cases against APIs, mapped to the OWASP API Security Top 10. Covers authentication, authorization, injection, data exposure, and rate-limiting. A single run reveals the real security posture of any endpoint.
Shellcode-Evasion-Suite
Python · Defense EvasionEvasion framework that studies detection signatures across AV/EDR engines on obfuscated payloads. Iterate evasion techniques — encryption, injection, syscall rerouting — and validate effectiveness against real defenses in-lab.
View sourceBloodHound-Parser
Python · Active DirectoryParses and prioritizes BloodHound attack paths to Domain Admin. Reduces noise from thousands of edges to an actionable set of critical paths, ranked by exploitation probability in the live environment.
View sourceShodan-Intel-Reporter
Python · Threat IntelCorrelates internet-exposed assets against the known CVE database. Automates remote entry-vector detection and generates prioritized reports that shorten the perimeter exposure window.
View sourceBugBounty-Automation-Setup
Shell · ReconProvisions reproducible pentesting environments from a clean instance in seconds. Preconfigures recon, enumeration, and exploitation tooling so the operator starts working with zero setup friction.
View sourceElite Training
HTB Certified Penetration Testing Specialist (CPTS)
ID: HTBCERT-04993356B2 · May 202610-day hands-on exam against an enterprise network. 100/100, with a final report commended by the HTB review team.
Certified Blue Teamer (CBTeamer)
The SecOps Group · Ene 2026DFIR, Splunk analysis, memory forensics, and Active Directory exploitation.
CARTS
Cyberwarfare LabsHands-on Red Team certification.
CAPE — Active Directory
Hack The Box · In progressCertified Active Directory Pentesting Expert. Advanced AD exploitation exam, in preparation.
Cyberwarfare Labs
Certified AD Red Team Specialist
ID: 697ea4d4fbb... | Feb 2026 VIEW CREDENTIAL
Certified Web Red Team Analyst
ID: 6983d6b090d... | Feb 2026 VIEW CREDENTIALHack The Box Pro Labs (100% Completed)
Approach
My work sits between two ideas: understanding how something breaks, and being able to explain it. I focus on Red Team and Active Directory because I enjoy chaining small flaws into a full compromise, always in authorized environments.
Over time I learned that exploitation is not enough: a finding only matters if the team receiving it can reproduce and fix it. That is why I treat the report with the same care as the exploit, keeping an auditor's independence and objectivity.
I keep studying every day. There is always something new to break and, now, to protect.