> For the complete documentation index, see [llms.txt](https://shohamshilo.gitbook.io/shohamshilo/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://shohamshilo.gitbook.io/shohamshilo/about/whoami.md).

# whoami

## The short version

I'm an aspiring penetration tester with a hands-on offensive-security portfolio and an unusual route into the field. Before security, I spent four years as a **combat Intelligence Officer** in the IDF a role built entirely around analysis, decision-making under pressure, and leading teams . That background shapes how I work: methodical, evidence-driven, and focused on communicating findings clearly to the people who need to act on them.

I'm **CompTIA PenTest+** certified and actively working toward **OSCP**, **CPTS**, and **CRTO**.

## How I got here

I started out writing software my first role was building interactive exhibit software at the Jerusalem Science Museum before my military service. That gave me a developer's instinct for how systems break.

During my service I lead intelligence teams in active operations, providing full intelligence support for ground forces and special operation units. The role was compromised of intelligent gathering, operational planning, briefing assessments up the chain of command and mission specific guidance in field conditions . The core skills are there, turning messy data into a clear picture, prioritizing under pressure, and writing assessments that decision-makers can actually use. These skills are directly transferable into penetration testing and and offensive security work. To sum up my job was think like the enemy and find its weaknesses.

Since then I've gone deep into offensive security: building recon tooling, writing proof-of-concept exploits, researching vulnerabilities in public bug-bounty programs, and grinding labs.

## What I'm looking for

A junior penetration tester or red-team role where I can contribute to real engagements, learn from experienced operators, and keep building. I care about doing the work properly — clean methodology, reproducible findings, and reports that lead to things actually getting fixed.

## How I think about offensive security

* **Enumeration wins.** Most of the work is in patient, thorough recon. Exploitation gets easier once you understand the target and the underling systems.
* **Manual over automated.** Scanners are a starting point, not an answer. The interesting findings come from understanding the application, not from a tool's output.
* **A finding nobody understands is a finding nobody fixes.** Clear, audience-aware reporting is the deliverable — the exploit is just the evidence.

## Outside the terminal

I'm a self-driven learner — most of what I know here is self-taught through labs, CTFs, write-ups, and a lot of trial and error. I document as I go, which is part of why this site exists.

***

➡️ Next: · [Projects](/shohamshilo/projects-and-tools/projects.md)
