Gaya KACI
cybersecurity student · web security researcher
Master’s student at Efrei Paris Panthéon-Assas Université. I work in web development and cybersecurity at Société Générale Assurance, where I research web security and build security tools.
/paris/fr
about
I build security tools and web software, backed by experience in network and systems administration.
At Société Générale Assurance, I research complex web targets, reverse engineer anti-bot systems, and study browser fingerprinting.
Outside work, I build small CLIs, browser tools, and AI projects. I work across Linux, macOS, and Windows, and usually read the source before the docs.
projects
selected open-source work · demos where available
- Python scraping framework built on Playwright.
ghostpwn (source, opens in new tab)
Autonomous pentest agent TUI interactive, multi-provider LLMteensy-reverse-shell (source, opens in new tab)
A BadUSB proof of concept using a Teensy 3.2 microcontroller to deploy a fileless PowerShell reverse shell on a Windows target.binje (source, opens in new tab)
A modern movie and TV show discovery web application built with Next.js, powered by TMDB API.spotblock (source, opens in new tab)
A cross-platform Bash script that blocks Spotify ads by modifying your system's hosts file. Works on both macOS and Windows!dns-switcher (source, opens in new tab)
A lightweight macOS menu bar app for instant DNS profile switching
contributions
1441 contributions in the last year · via github
writing
7 entries · notes and write-ups
Fix Vivaldi sidebars staying open after switching windows
An experimental local patch for stuck auto-hide sidebars in macOS Vivaldi 8.2.4133.52, with bundle checks, a backup, and restoration.· 3 minFix missing Gmail notifications on Android
A practical checklist for restoring Gmail alerts on Android, including notification channels, sound settings, Gmail sync, and an ADB fix for inconsistent permissions.· 3 minUnlock Brave Origin Without Paying
The Android Origin gate verifies subscription credentials against a public key the server hands back, with no issuer pinning. A local policy path never redeems them, so a forged credential is enough.· 4 minTuning Patchright for fingerprint-stats pages
Why AmiUnique and WebRTC leak tests need a different approach than bot-detection demos, and how WebSkrap handles them with native Chromium flags and opt-in context metadata instead of JavaScript spoofing.· 5 minPassing Bot Detection in Headless Chrome
Making headless Chromium clear the same bot-detection suite as headed mode with a simulated screen and a masked user agent, no JavaScript spoofing.· 4 minTeensy BadUSB reverse shell POC
HID keyboard injection on a Teensy 3.2 chains into a fileless PowerShell reverse shell on Windows.· 4 minSkia Graphite compositing bug in Chromium on macOS
A GPU rendering synchronization bug causing visual corruption on macOS, and how to fix it.· 4 min
skills
filled: regular use · outlined: occasional use
- security
- dev
- cloud / devops
- scraping / automation
- ai / ml
- data
- os
certifications
linked rows verify on credly
course badges
contact
email works best