| Fixture | Competition | Status | Detail |
|---|---|---|---|
| SOC Analytics | Yandex Practicum | 4mo, SOC monitoring | |
| DevSecOps Labs | EverSecure League | 21 flags | |
| AI-Pentest Track | CyberED Cup | 4/4 HW, certified | |
| Agent Security Week (SHAD) | Yandex Qualifiers | enrolled, lecture 1 done | |
| Bug Bounty | Open Programme | active hunt |
| # | Finding | Status | Detail |
|---|---|---|---|
| 1 | Forward-auth bypass — tinyauth | unanchored regex bypass, patched |
| # | Player | Position | Role |
|---|---|---|---|
| 1 | Burp Suite | GK | last line, sees every request |
| 9 | Nmap | ST | finds the opening |
| 4 | Wireshark | CB | reads everything on the wire |
| 10 | Python | CAM | scripts the whole play |
| 5 | Docker | CDM | holds the shape |
| 7 | Linux / Bash | RW | fast, everywhere |
full time — next kickoff tbd