guest@batyaboyo: /~
guest@bb:$
About Skills Projects Journey Blog Resume Contact
Available for opportunities

|

Fullstack Software Engineer & Offensive Security Practitioner — building secure applications, extracting data intelligence, and hacking systems across web, network, cloud, and Active Directory domains.

0+

Projects Built

0+

Attack Domains

0

Core Pillars

Who I Am

Batya Boyo - Fullstack Engineer and Ethical Hacker
BB

Batya Boyo

Fullstack Engineer • Data Analyst • Ethical Hacker

Fullstack Engineering Data Analysis Penetration Testing Network Security Bug Bounty Red Teaming

Fullstack engineering, data intelligence, and full-spectrum offensive security

I engineer reliable full-stack applications, conduct structured penetration tests across multiple attack surfaces, and extract clear intelligence from complex datasets.

My security work is driven by curiosity — I think like an attacker to help defenders. That means testing networks, not just websites; cracking Active Directory trust chains, not just login forms; and auditing cloud configurations alongside web APIs. Each engagement is scoped, authorized, and documented to professional standards.

Fullstack Software Engineering: Architecting resilient web applications with PHP/Laravel, Python/Django, TypeScript, Next.js, and RESTful APIs — with security built in from the ground up.

📊

Data Analysis: Querying, processing, and visualizing complex datasets using SQL, Python (Pandas, NumPy), and analytics toolchains to isolate trends, anomalies, and actionable insights.

🛡️

Ethical Hacking: I approach security from the attacker's perspective — mapping attack paths through web applications, internal networks, Active Directory forests, wireless environments, and cloud infrastructure. I conduct penetration tests, hunt bugs on HackerOne and Bugcrowd, and simulate adversarial campaigns as a Red Teamer, always operating under a signed scope agreement and following responsible disclosure throughout.

What I Do

Fullstack Software Engineering

  • PHP & Laravel Framework
  • Python, Django & Django REST Framework
  • JavaScript, TypeScript & Next.js
  • React & React Native
  • HTML5, CSS3, Tailwind CSS & Bootstrap
  • Node.js & RESTful API Architecture
📊

Data Analysis & Insights

  • SQL & Complex Relational Queries
  • Python Data Libraries (Pandas, NumPy)
  • System Metrics & Log Intelligence
  • Performance Tracking & Reporting
  • Anomaly Detection & Dataset Cleaning
  • MongoDB & NoSQL Data Modeling
🛡️

Ethical Hacking & Offensive Security

  • Web & API Pentesting — Burp Suite Pro, OWASP ZAP, SQLMap
  • Network Recon & Exploitation — Nmap, Masscan, Metasploit
  • Active Directory — BloodHound, Mimikatz, Impacket, CrackMapExec
  • Wireless Security — Aircrack-ng, Hashcat, Evil Twin Attacks
  • Cloud Security — Prowler, ScoutSuite (AWS & GCP)
  • Vuln Assessment — Nessus, OpenVAS, Nuclei

Featured Projects

Category:
Level:

My Journey

Pillar 01

Fullstack Software Engineering

Building scalable, secure full-stack web applications and backend systems using PHP/Laravel, Python/Django, TypeScript, Next.js, and RESTful APIs. Security is a design concern from day one — not an afterthought.

PHP / Laravel Python / Django TypeScript / Next.js
Pillar 02

Data Analysis & Intelligence

Processing, querying, and analyzing system metrics, logs, and complex datasets to deliver actionable intelligence, isolate anomalies, optimize performance, and support decision-making with evidence.

SQL & Pandas Log Analytics Anomaly Detection
Pillar 03

Ethical Hacking & Offensive Security

Security is where my technical curiosity runs deepest. I test systems the way real attackers do — probing web apps for injection flaws, pivoting through internal networks, chaining Active Directory misconfigurations into full domain compromises, sniffing wireless traffic, and misconfiguration-hunting in cloud environments. I've competed in bug bounty programs on HackerOne and Bugcrowd, and I approach red team exercises as end-to-end adversary simulations rather than isolated vulnerability scans.

Network Pentesting Active Directory Cloud Security Wireless Bug Bounty Red Teaming

Latest Articles

July 28, 2026

The 8-Phase Pentest Lifecycle Explained

Breaking down a professional penetration test from Scoping & Rules of Engagement through Exploitation, Post-Exploitation, Reporting, and Remediation Verification — across web, network, and AD targets.

Read More →
June 12, 2026

Active Directory Attacks: From Foothold to Domain Admin

A practical walkthrough of SMB relay attacks, Kerberoasting, BloodHound path analysis, Pass-the-Hash lateral movement, and DCSync — with defensive mitigations for each phase.

Read More →
May 3, 2026

CEH vs OSCP: Which Cert is Worth It in 2026?

A practical comparison of EC-Council's CEH and Offensive Security's OSCP — covering exam format, salary impact ($90k–$120k+), and which path suits penetration testers vs. security administrators.

Read More →

Let's Connect

Open to Opportunities

I'm actively seeking roles in fullstack engineering, data analysis, and offensive security (penetration testing, red teaming, bug bounty). Whether you have a position, a project, or just want to connect — I'd love to hear from you.

💻
𝕏
X (Twitter) x.com/batyaboyo