About

Paulo Rigonato — Cybersecurity Professional

I work in cybersecurity with a focus on offensive security, pentesting, AppSec, Red Team operations, and applied research. This site brings together technical analysis, hands-on studies, tools, labs, and reflections on how real attacks are planned, executed, and detected.

The goal of paulo.seg.br is not to sell shortcuts or repeat generic checklists. The idea is to discuss tradecraft, limitations, operational impact, and technical decisions that appear in real security assessments.

Certifications

  • OSCP — OffSec Certified Professional (Offensive Security)
  • eWPTXv2 — Web Application Penetration Tester eXtreme (INE)
  • ITIL v4 — ITIL Foundation (Axelos/PeopleCert)

Areas of Focus

  • Pentesting for web applications, APIs, mobile targets, and infrastructure.
  • Red Team operations, adversary simulation, and control validation.
  • Active Directory, identity security, and attack paths in enterprise environments.
  • AppSec, architecture review, and controlled exploitation of security flaws.
  • Development of tools, automations, and security labs.
  • Technical content on AI applied to offensive and defensive security.

About paulo.seg.br

The blog publishes content for professionals who already work with security in practice: pentesters, red teamers, security engineers, AppSec professionals, and technical leaders who need to understand not only the vulnerability, but also the attacker mindset and the business impact.

When an article mentions products, labs, books, or tools with referral links, the policy is described on the Affiliate Disclosure page.

Contact

For article suggestions, corrections, technical discussions, or professional inquiries, use the Contact page.