"Security is not a product, but a process" - Bruce Schneier
Hi there! I'm Rafa Ponce Vivancos, a cybersecurity professional based in Spain. I focus on building and securing modern systems, with an emphasis on practical defense, offensive security methodologies, and automation.
- 🛡️ Focus Areas: Cybersecurity, Ethical Hacking, Network Security
- 💻 Development: Web Applications, Security Tools, Automation
- 🔎 Security Work: Threat analysis, hardening, detection engineering, incident response support
- 🌱 Currently Exploring: Cloud Security, DevSecOps, IoT Security
- 🎯 Goal: Making the digital world safer through measurable security improvements
🔍 More About My Journey
I work across offensive and defensive security: assessing systems, identifying weaknesses, and implementing controls that reduce risk in real environments. I’m especially interested in the intersection of engineering and security—where automation, visibility, and secure-by-default design make the biggest difference.
I approach cybersecurity as a blend of technology, people, and process. That mindset guides how I build, test, monitor, and improve systems over time.
💻 Active Projects
- Ghostkey Project - C2 server infrastructure with Go/Python backend
- NetTool - Open-source project focused on network diagnostics tool
- Security Research & Tooling - Ongoing research, internal tooling, and security automation
📝 CTF Write-ups & Security Notes
- 🔐 TryHackMe: Mr. Robot Walkthrough - Complete walkthrough with privilege escalation
- 🌐 OWASP Top 10 Analysis - Deep dive into web application vulnerabilities
- 🛡️ Network Defense Strategies - IDS/IPS implementation and monitoring
- ☁️ Cloud Security Best Practices - AWS & Azure security configurations
⭐ Star my repositories if you find them useful!
"The best defense is a good offense, but the best offense is understanding."






