Available for opportunities

Massimo Massetti

Cybersecurity Researcher & Developer

OSCP Candidate · Bug Bounty Hunter · AI Security Research

massimo@portfolio:~$
$ whoami
massimo — security researcher
$ cat skills.txt
pentesting, python, bug bounty, AI/LLM, systems
$ uptime
active since 2023, 0 days idle
$

01 About

Computer Science student at Université de Caen Normandie with a strong focus on offensive and defensive cybersecurity. Currently preparing for the OSCP certification through OffSec's PWK labs.

Active bug bounty hunter on HackerOne and YesWeHack, invited to private programs of major French groups across insurance, energy, finance, healthcare, and defense sectors. Notable findings include XSS vulnerabilities at Groupe Les Mousquetaires and session manipulation flaws at fintech companies.

Working as an RLHF expert at Outlier, fine-tuning Large Language Models for improved alignment and robustness. Passionate about the intersection of AI and cybersecurity.

OSCP In preparation
H1 / YWH Bug Bounty Platforms
3 Languages spoken
RLHF AI Expert @ Outlier

02 Projects

🔬

AI Security Research Platform

AI-driven behavioral analysis system for defensive cybersecurity research. Uses LLM for real-time system interaction analysis and automated threat classification with MITRE ATT&CK mapping.

PythonLLMParamikoDockerYAML
⚔️

Offensive Security Framework

Automated security testing framework with multi-model AI integration. Combines vulnerability scanning, exploit research, and intelligent payload generation in a unified pipeline.

PythonAI/LLMBurp SuiteNuclei
🧪

Security Lab Infrastructure

Training environment for security research. Modules include shellcode/BOF development, automated reconnaissance playbooks, credential parsing (DPAPI), and evasion mechanisms with AES/XOR encryption.

PythonCPyCryptodomeMinGW
🏴‍☠️

Bug Bounty Hunting

Active on HackerOne & YesWeHack. Invited to private programs of major groups (insurance, energy, finance, healthcare, defense). Notable findings: XSS at Groupe Les Mousquetaires, session manipulation at fintech companies.

XSSSQLiSessionIDORCWE

03 Skills

> cybersecurity

Pentesting Active Directory OWASP Vulnerability Research Network Security Bug Bounty

> development

Python C C# PHP SQL HTML/CSS Solidity

> tools

Kali Linux Metasploit Burp Suite Wireshark Git Docker Nmap

> ai_&_research

RLHF Fine-tuning LLM Security Model Alignment

04 Contact

Interested in working together or have a question? Feel free to reach out.