Skip to content
View JBMTP07's full-sized avatar

Block or report JBMTP07

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JBMTP07/README.md

Hey, ich bin Josef. 👋

Penetration Tester & Security Researcher. Seit 2020 in Bug Bounty aktiv (HackerOne & Bugcrowd, 20+ verifizierte Findings in privaten / invite-only Programmen), regelmäßig auf HackTheBox, ehrenamtliche Vorträge an bisher 8 Schulen zu KI-Sicherheit und Cybersecurity. Background aus der industriellen Automatisierung (Siemens S7, SCADA) — direkter Zugang zur OT/ICS-Security.

🎯 Offen für Pentest-/Red-Team-Rollen — Remote weltweit oder Deutschland. 🛡️ Betreibe [JB] Security, eigene Freelance-Pentest-Praxis: jb-security.de


Was ich mache

  • Penetration Testing — Web, API, Netzwerk, Active Directory
  • Bug Bounty — private & invite-only Programme (HackerOne, Bugcrowd), Schwerpunkt Business-Logic & Exploit-Chains
  • Red Team — Homelab mit isoliertem AD, HTB, eigene dokumentierte Methodik
  • OT/ICS Security — Siemens S7, SCADA, IT/OT-Schnittstellen
  • Security Awareness — Vorträge an Schulen zu LLMs, KI-Risiken & Cybersecurity

Tools & Skills

Offensive:    Burp Suite Pro · Metasploit · Nmap · ffuf · sqlmap · Hydra · Nessus · Wireshark
AD/RedTeam:   BloodHound · Impacket · CrackMapExec · Kerberoasting · AS-REP Roasting · RBCD · ADCS
Scripting:    Python · Bash · PowerShell · JavaScript
OT/ICS:       Siemens S7 (SPS) · SCADA · Industriesteuerungen · Feldbusse
OS:           Kali Linux · Parrot OS · Windows Server · Active Directory · Docker

Repos

Repo Inhalt
🛡️ jb-security [JB] Security — Freelance-Pentest-Site (Web, AD, OT/ICS · OWASP, PTES, NIST, MITRE)
🔴 bug-bounty-reports Sanitisierte Bug-Bounty-Reports — Chained RCE (CVSS 9.9), Command Injection (CVSS 9.8)
HTB-Writeups Deutsche Writeups für retired HTB Machines — komplette Angriffsketten von Recon bis Root
Study-Notes Methodik-Playbook: AD-Angriffe, Linux/Windows PrivEsc, Nmap, Burp, Reporting
JBMTP07.github.io Portfolio & CV

Zertifizierungen (2026)

Zertifizierung Anbieter Status
Security+ (SY0-701) CompTIA Bestanden 05/2026
Network+ CompTIA 📅 Prüfung 06–07/2026
Linux+ CompTIA 📅 Prüfung 06–07/2026
PenTest+ CompTIA 📅 Prüfung 06–07/2026
CEH v13 EC-Council 📅 Prüfung 06–07/2026
OSCP OffSec 🎯 Geplant Q4 2026

Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger)


GitHub Stats

Stats


Kontakt

📧 josefbasner@proton.me 🌐 jbmtp07.github.io · jb-security.de 🌍 Deutschland · Remote weltweit möglich

Popular repositories Loading

  1. HTB-Writeups HTB-Writeups Public

    Deutsche HTB-Writeups — komplette Angriffsketten von Recon bis Root: AD (RBCD, ADCS), Linux/Windows PrivEsc, CVE-Exploitation

  2. Study-Notes Study-Notes Public

    Pentest methodology notes: AD attacks, Linux PrivEsc, Nmap enumeration, Burp workflow

  3. JBMTP07 JBMTP07 Public

    GitHub profile README — Penetration Tester · Bug Bounty · OT/ICS Security

  4. JBMTP07.github.io JBMTP07.github.io Public

    Portfolio & CV — jbmtp07.github.io

    CSS

  5. bug-bounty-reports bug-bounty-reports Public

    Sanitized bug bounty writeups — chained exploits, RCE, web app pentesting

  6. jb-security jb-security Public

    [JB] Security — Freelance Penetration Testing für Web, AD und OT/ICS · 20+ Findings auf HackerOne & Bugcrowd · OWASP, PTES, NIST, MITRE

    HTML