Skip to content
Available · Internship / Alternance

Steevy Tongoue Bagofa

Offensive Security Student

Third-year computer engineering student at ESIEA, Paris, focused on offensive security. I build my own labs and tooling, practice on Hack The Box, and compete in CTFs. Looking for a supervised role to learn fast and contribute.

Hack The Box

Level 33 · Skilled

CTF

1st Place — Red Shielders Africa

Availability

Alternance / internship

Location

Paris, France

Projects

Education

  • ESIEA2026 – 2029

    Engineering Degree — Computer Engineering

  • UCAC-ICAMSeptember 2024 – July 2026

    Preparatory Cycle — Engineering

  • Maarif International College2017 – 2024

    Secondary education

steevy.osv1.0

Open to alternance & internshipsParis, France

Build.Break.Understand.

Steevy Tongoue
Bagofa

Offensive Security · Student / Engineer in training

Computer engineering student in Paris. I break web apps, Active Directory and networks — then document exactly how.

About

I don't just study security. I break it — on purpose.

Third-year computer engineering student at ESIEA, Paris — heading straight for offensive security. I learn by breaking things, then understanding exactly why they broke.

Hack The Box, my own vulnerable infrastructure, security tooling in Rust, CTFs. I don't wait for the syllabus: I build the environments, attack them, and read the logs from the other side.

🏆 1st PlaceRed Shielders Africa CTF

2026 · Team of four. Web, network and forensics — solved under pressure. First place overall.

Currently

  • Studying computer engineering at ESIEA
  • Practicing penetration testing
  • Working through Hack The Box
  • Building Farstyle in Rust
  • Developing vulnerable security labs
  • Practicing Active Directory security
  • Learning through CTFs
The Lab

Environments I built and broke

Not screenshots of tools I used — things I stood up myself. A security tool, an offensive lab, a defensive lab. Poke at them.

01Actively developed

Farstyle — Security Auditing Platform

Built because I wanted my own security toolbox.

A native Rust desktop auditing platform: interception proxy, repeater, intruder, a pluggable module engine and an AI workspace, in a single binary.

Full case study
Farstylev0.x · dev build
GET /login HTTP/1.1
Host: target.local
 
Intercepted
Modified
Forwarded

Requests pause here so I can read them, tamper, and replay.

02Personal Lab

Vulnerable Web Application Lab

If you build the target, you understand the attack differently.

A self-hosted, segmented environment to practice realistic web attack chains end to end — from the reverse proxy and WAF down to the database.

Full case study
Internet / Attacker

Traffic originates from an untrusted position, as it would in the real world.

click a hop to inspect

03Personal Lab

Segmented Network & Monitoring Lab

Same attack. Different perspective.

A multi-zone network with pfSense, DMZ and internal VLANs, plus Snort IDS and a Wazuh SIEM — the defensive view of the same attacks I practice offensively.

Full case study
pfSense

Firewall/router enforcing routing and rules between every zone.

Detection pipeline

How I Work

Same six moves, every box

How I approach every lab and machine. It's my method — not client engagements.

0101

Recon

Understand the target and map the attack surface.

0202

Enumerate

Identify services, technologies, users, attack vectors and misconfigurations.

0303

Exploit

Validate vulnerabilities in a controlled environment.

0404

Escalate

Understand how initial access can lead to greater privileges.

0505

Detect

Study what defensive controls see.

0606

Document

Turn technical findings into structured reports and lessons learned.

./interact

Interact with the system

A harmless little demo of how I think. Nothing here is a real endpoint — it's a picture of the mindset: map the system first, then understand how it breaks.

recon — target: steevy.localsimulation
portservice
  • 22SSH
  • 80HTTP
  • 443HTTPS
  • 3000NEXT.JS

Four services exposed. Want to see the attack surface?

Hands-On Training

Where theory gets tested

Real machines, real challenges, real time pressure. Numbers I can point to — not a reading list.

Hack The Box

@Farstyle

Profile

33

Level

Skilled

Rank

What I actually practice

Linux

priv-esc, services, misconfigs

Windows

tokens, services, UAC

Web

the way in, most of the time

Active Directory

Kerberos, LDAP, SMB

Privilege Escalation

user → root / SYSTEM

Enumeration

the part everyone skips

I work through Linux and Windows machines involving enumeration, exploitation and privilege escalation, and I practice Active Directory attack paths using Kerberos, LDAP, SMB, BloodHound, Impacket and NetExec — documenting each machine as a structured attack chain.

1st Place

Red Shielders Africa CTF

2026 · Team of four · Regional cybersecurity meetup

Challenges solved

WebNetworkForensics

Under the hood

TeamworkTime pressureCoordination

click the trophy

Also grinding

  • PortSwigger Web Security Academy

    Authentication learning path completed.

  • CyLab Security Academy

    24 CTF challenges solved — 20 easy, 4 medium.

  • TryHackMe

    Apprentice — 7 rooms covering pentesting fundamentals and content discovery.

Education

Academic path

ESIEA

2026 – 2029

Paris, France

Engineering Degree — Computer Engineering

Entering 3rd year. Cybersecurity specialization from year 4.

UCAC-ICAM

September 2024 – July 2026

Douala, Cameroon

Preparatory Cycle — Engineering

Maarif International College

2017 – 2024

Cameroon

Secondary education

Off the clock

A real person, not a résumé

Fast reflexes, competition, and taking systems apart for fun. It's all kind of the same thing.

🎾

Tennis

Fast hands, faster decisions.

🏓

Table tennis

Same reflexes, smaller table.

🏀

Basketball

Team game. I like those.

🎮

Video games

Systems to take apart, for fun.

steevy@sec — zsh

$

Current objectiveAvailable

Find the next challenge.

I'm looking for a cybersecurity internship or work-study / alternance — the right environment to learn from people who've done this for real, contribute to actual projects under supervision, and keep getting sharper. Point me at a target.

Role

Internship · Work-study

Commitment

Alternance or internship · Paris / Remote

Based

Paris, France

steevyvalery7@gmail.com