Théo Schwartz
Cybersecurity Student · Paris
ABOUT
Who
19, student at IPSSI (2025‑2028), Paris. I build security tools that actually solve real problems. I’m fascinated by how code breaks and how systems fail.
Am
I’m from Annecy, now living in Paris for my studies. I learn by doing, testing my own projects, and hunting for flaws. I move a lot—not randomly, but to explore, understand, and create.
I
Pragmatism above all. Build, fix, document. My code solves real problems, not egos. Hard bugs, broken systems… that’s where I learn the most.
TECHNICAL SKILLS
Languages
Security Tools
Environment
CERTIFICATIONS
3 completed · 89% avg. module score
SecNumacadémie
ANSSI — Agence nationale de la sécurité des systèmes d'information
Atelier RGPD
Commission Nationale de l'Informatique et des Libertés
Linux Unhatched
Networking Academy (Cisco Networking Academy)
PROJECTS
4 shipped · ~3,000 lines of code · all open source
View on GitHubhttp-garden
Differential HTTP analysis engine. Research on request smuggling by comparing parser interpretations across Nginx, HAProxy, and Gunicorn using AFL++.
- Fuzzing: Differential analysis using AFL++ on multiple targets.
- Trophies: Found vulnerabilities in HAProxy (CVE-2023-40225) and others.
- Environment: Composable Docker architecture with custom Python REPL.
Password Analyzer
Built because I got tired of guessing password strength. Entropy scoring that actually works, pattern recognition for keyboard walks, predictable substitutions. Estimates real-world crack time using GPU benchmarks.
- Scoring: entropy-based strength with practical heuristics.
- Patterns: detects keyboard walks and common substitution habits.
- Estimation: crack-time approximation using GPU benchmark baselines.
Web Vuln Analyzer
My first real security tool. Automates the boring part, testing. Finds SQLi, XSS, CSRF, path traversal, parameter pollution. The insight: generate context-aware payloads.
- Automation: crawl + test loop to reduce manual recon.
- Coverage: targets SQLi, XSS, CSRF, traversal, parameter pollution.
- Payloads: context-aware generation rather than naive fuzzing.
Steganography Toolkit
LSB steganography, EXIF manipulation, metadata injection. Hide data in images imperceptibly — the eye won't catch what statistics can't explain.
- Techniques: LSB steganography + EXIF/metadata manipulation.
- Workflow: hide + extract utilities designed for real scenarios.
Interactive Narrative Engine
Passion project. Interactive fiction engine built on state machines. Branching dialogue with real consequences. Built to prove a thesis: games and serious tools are the same architecture.
- Core: state-machine driven story logic.
- Design: branching dialogue with meaningful consequences.
- Architecture: tool-like structure applied to game systems.
CONTRIBUTIONS
EDUCATION
Lycée Lachenal
Baccalauréat STI2D
- Systèmes techniques, ingénierie et numérique.
- Machines, réseaux et logique technique.
- Base solide pour comprendre des environnements techniques.
Program
- Baccalauréat STI2D
- Approche systèmes et ingénierie
- Annecy, France
Subjects
- Computer & Digital Sciences
- Mathematics
- Engineering Sciences
- Physics-Chemistry
Projects
- IoT sensor networks
- Embedded Linux systems
- Network protocols
- Industrial automation
IPSSI — Bachelor Cybersecurity
Sécurité offensive · Architecture système
- Architecture système, réseaux et sécurité offensive.
- Analyse des mécanismes, des vulnérabilités et des défenses.
- Pratique de Linux, du test d’intrusion et des outils de sécurité.
Program
- Bachelor Cybersecurity
- Year 1 (2025-2026)
- Expected end: 2028
- Paris, France
Modules
- System architecture
- Network protocols & security
- Offensive security
- Linux administration
- Penetration testing
Tools
- Kali Linux, Metasploit
- Burp Suite, Wireshark
- Nmap, OWASP Tools
- John the Ripper
PRACTICE PLATFORMS
CONTACT
Let's Connect
Feel free to reach out for any opportunity, collaboration, or question.

