Francesco Soncina is an Ethical Hacker and Red Teamer with 11 years of hands-on experience blending offensive security and full‑stack development, currently testing and hardening systems at ABN AMRO in Amsterdam. Certified with OSCE and OSCP, he brings deep exploit development and tool-building skills—evidenced by contributions to Metasploit and the PEzor packer where he extended payload formats and refined remote code execution modules. Comfortable across JavaScript stacks and blockchain projects, he has led development at Bloqhouse and founded community initiatives like Bologna Tech Scene while serving on BolognaJS staff. A regular CTF player and staff member in developer communities, he pairs pragmatic engineering with creative adversary thinking to reveal realistic attack paths and improve defenders’ posture.
11 years of coding experience
2 years of employment as a software developer
Bachelor's degree, Computer Science, 102, Bachelor's degree, Computer Science, 102 at Alma Mater Studiorum – Università di Bologna
Contributions:3 reviews, 110 commits, 47 PRs in 2 years 1 month
Contributions summary:Francesco primarily contributed to adding support for different output formats like DLL, reflective DLL, and service executables. They updated the build scripts to accommodate these new output types. Moreover, the user integrated features such as the ability to fluctuate memory regions and inject code. They have been working on enhancing the tool to include module stomping and also implemented and tested some environment variable keying functionality.
Contributions:79 commits, 17 PRs, 81 comments in 1 year 9 months
Contributions summary:Francesco primarily contributed to the Metasploit Framework by creating, refactoring, and updating an exploit module related to a remote code execution vulnerability in the Nanopool Claymore Dual Miner APIs. Their work involved adding the exploit module, fixing bugs, refactoring code for improved readability and efficiency, and updating the module's references and exploit functionality, thus enhancing the framework's capability to address security vulnerabilities. The changes involved modifying exploit code, including platform-specific configurations for both Windows and Linux.
metasploitmetasploit-framework
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.