// established presence · 0x6c6f72657469
whoami
red-teamer · builder & teacher
I'm Ludovico Loreti, aka n4pst3r. I've spent close to twenty years figuring out how systems break, so I can stop them. Right now I'm the Regional Information Security Officer for EMEA & APAC at a publicly listed fintech.I lead security and AI for a defence & aerospace group: I own both cyber and AI risk, I build the tools my teams actually use, and I teach ethical hacking. This page is a terminal. Treat it like one.
Tip the terminal below is real. type help to start.
00 origin story
Where the name comes from, and where it points now.
It started around 2004, in Call of Duty and the clan forums around it. I was a kid who needed to know how everything worked: the game, the servers, the people on the other side of the screen. That itch never stayed inside the game. Somewhere along the way I became n4pst3r.
For a while it ran ahead of my judgement. It went back to 2010 and 2011; by the time it reached a courtroom in 2013 I had long moved on. The court found it was never for money. I owned it, I learned from it, and I closed that chapter for good.
Everything since has been on the other side of the same skill. Penetration testing and digital forensics. An application-security practice I built from scratch. Years running security across a publicly listed fintech. Today I'm the Regional Information Security Officer for EMEA & APAC there, holding cyber risk and AI risk in the same pair of hands.And today I lead security and AI for a defence & aerospace group, holding cyber risk and AI risk in the same pair of hands. I also teach Web Application Security and Ethical Hacking, because I would rather the next curious kid learn it the right way.
know how things break, and you'll know how to keep them standing.
01 interactive shell
A live command line. Try help, repos, or something undocumented.
02 agentic security
(Semi-)autonomous agents as governed security probes and orchestrators, and the research behind them.
// what I run
03 OWASP · AI & LLM
The standards worth knowing for securing AI and LLM systems.
| # | resource | summary | tags | open |
|---|
04 LLM red-team field notes
Know the offense, or you can't run the defense.
// defences that hold
05 old school operator cheatsheet
Battle-tested payloads, cleaned up. $c2ip = your C2 / listener, $c2port = its port.
Click any block to copy.