Gaya KACI
cybersecurity student · web security researcher
Master's student at Efrei Paris Panthéon-Assas Université. Currently working in web development and cybersecurity at Société Générale Assurance doing web security research and building security tooling.
/paris/fr
about
Cybersecurity-focused developer with a background in network and system administration, plus web development.
Day job at Société Générale Assurance: web security research against complex web targets, reverse-engineering anti-bot and bot-detection systems, and browser fingerprinting.
Outside work, I build small CLIs, browser tools, and AI side projects. Comfortable across Linux, macOS, and Windows. I usually read source before docs.
projects
selected open-source work · source and live demos where available
- webskrapPython scraping framework built on Playwright.
- ghostpwnAutonomous pentest agent TUI interactive, multi-provider LLM
- teensy-reverse-shellA BadUSB proof of concept using a Teensy 3.2 microcontroller to deploy a fileless PowerShell reverse shell on a Windows target.
- binjeA modern movie and TV show discovery web application built with Next.js, powered by TMDB API.
- spotblockA cross-platform Bash script that blocks Spotify ads by modifying your system's hosts file. Works on both macOS and Windows!
- dns-switcherA lightweight macOS menu bar app for instant DNS profile switching
contributions
758 contributions in 2026 · via github
writing
5 entries · notes and write-ups
- The Android Origin gate verifies subscription credentials against a public key the server hands back, with no issuer pinning. A local policy path never redeems them, so a forged credential is enough.2026-06-30 · 4 min
- Why AmiUnique and WebRTC leak tests need a different approach than bot-detection demos, and how WebSkrap handles them with native Chromium flags and opt-in context metadata instead of JavaScript spoofing.2026-06-07 · 5 min
- Making headless Chromium clear the same bot-detection suite as headed mode with a simulated screen and a masked user agent, no JavaScript spoofing.2026-06-03 · 4 min
- HID keyboard injection on a Teensy 3.2 chains into a fileless PowerShell reverse shell on Windows.2026-05-07 · 4 min
- A GPU rendering synchronization bug causing visual corruption on macOS, and how to fix it.2026-05-06 · 4 min
skills
- security
- dev
- cloud / devops
- scraping / automation
- ai / ml
- data
- os