Home About Articles Contact
systems nominal · node heric.bz
STATUS OPERATIONAL ROLE OFFENSIVE SECURITY TZ GMT-3

About // Operator

Heric Baldez

I break into systems for a living — legally, under contract, and with a paper trail. Penetration tests, red team operations, bug bounty hunting and OSINT-driven investigations, delivered as reproducible evidence: how it broke, what that means for you, and exactly what it takes to close the gap.

// global recon live · drag to rotate
heric@bz — ~/ops
$ cat operator.json
{
"name": "Heric Baldez",
"alias": "Sr. Monge / Monge0x11",
"role": "offensive security & digital investigation",
"focus": ["pentest", "bug bounty", "red team", "OSINT"],
"stack": ["node.js", "python", "burp", "nmap"],
"languages": ["pt-BR", "en"],
"base": "Brazil / GMT-3",
"model": "scoped, authorized, evidence-driven",
"status": "taking engagements"
}
$ ./engage
uptime
5+
years operating
challenges
50+
CTF solved
scope
100%
authorized & ethical
status
OPEN
taking engagements
public record // 0x01

Verifiable, not just claimed

don't take my word for it
expertise // 0x02

Core Competencies

Work with me →
0x01

Digital Investigation

OSINT, digital footprint analysis, attribution and threat mapping — turning scattered public signals into a clear, defensible picture.

0x02

Pentest & Bug Bounty

Hands-on assessment of web apps, APIs, networks and mobile — from scoped engagements to public bug bounty programs, always with reproducible findings ranked by real-world impact.

0x03

Red Team Operations

End-to-end adversary simulation that tests detection and response against realistic attack paths — not checklists or assumptions.

0x04

Security Development

Custom tooling and automation in Node.js and Python to scale recon, monitoring and reporting across engagements.

services // 0x03

What I Offer

Start a project →
SEC

Security Assessment

Penetration testing, bug bounty hunting and vulnerability assessment across web, API and infrastructure — delivered with clear reports and fixes ranked by exploitability.

Request a scope →
INV

Digital Investigation

OSINT and digital forensics for incident response, fraud and attribution — evidence collected and handled with a defensible chain of custody.

Open a case →
RED

Red Team

Goal-based adversary simulation that measures how far an attacker reaches and how quickly your team detects and responds.

Plan an engagement →
method // 0x04

How an engagement runs

start to close
PHASE 01

Scope & Authorization

Written authorization, defined targets and rules of engagement — before a single packet moves.

PHASE 02

Recon & Mapping

Passive and active mapping of the attack surface — the system as an adversary actually sees it.

PHASE 03

Exploit & Evidence

Controlled exploitation with minimal-impact PoCs. Every claim is demonstrated, never assumed.

PHASE 04

Report & Debrief

Findings ranked by real exploitability, with evidence a developer can replay and fix directly.

PHASE 05

Retest & Verify

Fixes verified against the original attack path — closed means proven closed, not assumed closed.

principles // 0x05

How I operate

non-negotiable
01

Scope first

Nothing is touched without written authorization and a clearly defined boundary. The rules of engagement come before the engagement.

02

Evidence over assertion

Every finding ships with reproducible proof and a real-world impact rating — not a scanner screenshot and a severity guess.

03

Confidential by default

Engagements, data and findings stay between us. Discretion is part of the deliverable, not an upsell.

04

Disclosure, not weaponization

Vulnerabilities are reported so they get fixed. The same skill that finds a flaw is used to help close it.

media // 0x06

Media & Appearances

YouTube
@AyrtonYamin · 2025

SEUS DADOS ESTÃO EM RISCO! VEJA O QUE DISSE O HACKER PROFISSIONAL

Conversa no programa Entre Nós sobre segurança digital, privacidade de dados e os erros que expõem clientes sem que os próprios desenvolvedores percebam.

Watch on YouTube →
@CanalPodtecno · 2025

HACKING, INVESTIGAÇÃO DIGITAL E PERÍCIA: a verdade nua sobre o submundo digital

Como atacantes operam na prática, onde nascem as vulnerabilidades e o que realmente fortalece a segurança — com técnicas de investigação online, OSINT e casos reais.

Watch on YouTube →
next step

Have a system worth testing?

A penetration test, a red team engagement, or a digital investigation — tell me what you're protecting and I'll come back with concrete next steps at contact@heric.bz.