BSc thesis · Flagship
CTF Hammer
A unified workflow for capturing, parsing, and reviewing Attack/Defense CTF traffic without stitching together the operator experience by hand.
CTF HammerComputer Science × Infrastructure Security
I’m Edoardo Balzano, a University of Turin Computer Science graduate and MSc Cybersecurity student at Politecnico di Torino. My work sits where Linux, containers, networks, and practical attack/defense meet.
Currently in Turin, completing my MSc in Cybersecurity · Open to security and infrastructure opportunities
Evidence, not adjectives
Each claim below points to a project, a lab, or an experience. Select a lens—or read every item with JavaScript disabled.
BSc thesis · Flagship
A unified workflow for capturing, parsing, and reviewing Attack/Defense CTF traffic without stitching together the operator experience by hand.
CTF HammerSecurity tooling
A modular Python pipeline for feature extraction, heuristic classification, LLM-assisted assessment, CLI use, and functional tests.
HTA & JAR analyzerSabancı coursework · Team
A simulated water-treatment SCADA environment used to explore Docker isolation and an SQLi → SSRF → unauthorized Modbus write chain.
AquaSecureNational training program
Represented the University of Turin in the 8th edition after hands-on web, binary, crypto, network, and Attack/Defense training.
Continuous practice
Machine and challenge work used to turn reconnaissance, exploitation, and post-exploitation into a repeatable written process.
Hack The BoxReasoning trail
Technical records of attack paths, including assumptions, failed branches, evidence, and remediation context.
WriteupsSelf-hosted lab
A compact environment for containerized services, private access, controlled exposure, upgrades, and troubleshooting.
Operated service
A real containerized workload for practicing deployment, persistence, access paths, service upkeep, and recovery thinking.
Exploration
OpenClaw is an exploration area for understanding the boundaries and resource demands of local AI workloads—not a claimed production service.
Front-of-House Manager
Coordinates reservations, suppliers, cash, inventory, team flow, guest experience, and stewardship of an 80+ label wine cellar.
2025/26 exchange
Independent study in Istanbul, technical collaboration in English, and adaptation to a new academic and cultural environment.
Front of house
Built the reliability, pace, and clear communication needed to keep guest-facing operations moving under pressure.
Selected work
The flagship began as a practical response to Attack/Defense CTF friction. The supporting projects extend that work into malware analysis and OT/ICS exposure.
Flagship · BSc thesis
A unified A/D CTF traffic-analysis workflow using tshark, async workers and a live web interface.
CTF Hammer collects PCAP traffic from vulnerable hosts, parses conversations with tshark, classifies useful patterns, and streams results into a web interface. Async workers keep analysis away from the operator path; SSH/SCP and Docker Compose connect the pieces.
Supporting security project
A Python analyzer for HTA/JAR feature extraction, explainable heuristics and model-assisted context.
A modular pipeline extracts features from HTA and JAR files, applies explainable heuristic rules, and can ask language models for a second assessment. CLI entry points and functional tests make each stage inspectable.
View projectSabancı coursework · Collaboration
A simulated water-treatment SCADA security exercise with Docker isolation and an SQLi → SSRF → Modbus write chain.
The team isolated services with Docker networks and modeled an attack chain from SQL injection to SSRF and an unauthorized Modbus write. It demonstrates applying security concepts to an OT/ICS-shaped environment—not professional industrial-security expertise.
View project
CTF Hammer / architecture
A site-native redraw of the thesis architecture: capture, queue, analysis, storage, and live presentation are separated so slow work does not block the operator.
Operate
A sanitized view of the Raspberry Pi 5 Docker host. Public and private access paths stay separate; domains, addresses, and ports are intentionally omitted.
No domains, IPs, or ports published
International experience
The 2025/26 Sabancı exchange adds independence, English communication, and cross-cultural teamwork to the technical work—including the AquaSecure coursework project.
Open certificate previewVerified credential
Official certificate of participation as a finalist. No uncertain team placement is claimed.
Download original PDFExternal profiles
Explore the repositories behind the projects, my hands-on security activity, and my professional profile.
@Proibito04
Source code for security tooling, infrastructure experiments, and selected academic projects.
Open profileHands-on security practice
Machines and challenges used to develop repeatable reconnaissance, exploitation, and documentation habits.
Open profileEdoardo Balzano
Education, international experience, technical direction, and professional background in one place.
Open profile