Skip to content

João Carlos Chavatte

Engenharia Backend | AppSec | DevSecOps

Summary

Profissional de tecnologia com atuação prática em Segurança de Aplicações (AppSec), DevSecOps e Engenharia Backend. Desde 2022, desenvolve ferramentas de SecOps, APIs, automações e laboratórios de pesquisa ofensiva, conectando desenvolvimento de software, infraestrutura Linux/cloud e segurança. Experiência com Node.js/TypeScript, Python e Java, Docker, CI/CD, bancos de dados e automação de segurança, com foco em Shift-Left, supply chain security e construção de soluções resilientes.

Skills

Application Security

  • AppSec
  • OWASP Top 10
  • DevSecOps
  • Shift-Left
  • Hardening
  • Secure Architecture

Offensive Security

  • Red Team
  • Threat Hunting
  • OSINT
  • Security Research
  • DNS Analysis
  • Stress Testing

Backend Engineering

  • Node.js
  • TypeScript
  • Express
  • Java
  • Python
  • FastAPI
  • REST APIs
  • Authentication
  • Authorization
  • Software Architecture

Cloud & Infrastructure

  • Linux
  • Shell
  • Docker
  • CI/CD
  • Git
  • GitHub
  • AWS
  • Azure
  • WSL2
  • ARM
  • Raspberry Pi

Data & Automation

  • PostgreSQL
  • MongoDB
  • SQLite
  • Security Automation
  • AI Automation
  • Observability
  • Risk Analysis

Engineering Practices

  • Scrum
  • Git Flow
  • TDD
  • Clean Code
  • SOLID
  • Design Patterns

Work Experience(1)

Dec 2021 - Current
Pesquisador de Segurança e Desenvolvedor
Chavatte Security
  • AppSec
  • DevSecOps
  • SecOps
  • Red Team
  • Backend Engineering
  • Node.js
  • TypeScript
  • Python
  • Java
  • Docker
  • Linux
  • Supply Chain Security

Pesquisa e desenvolvimento aplicado em AppSec, DevSecOps, SecOps, engenharia backend e segurança ofensiva.

  • Condução e publicação de PoC sobre Android/Open DNS Resolvers em LAN, com análise de DNS Tunneling e stress test de 1.500 QPS.

  • Desenvolvimento do Sentinel OPS para varredura de repositórios GitHub, detecção automatizada de vulnerabilidades e credenciais expostas e apoio à governança de risco.

  • Arquitetura do Enoch Engine API, boilerplate backend production-grade em Node.js/Express com Anti-DoS, Token Versioning, Graceful Shutdown, uploads em stream e Multi-Schema via Docker.

  • Concepção do ParrotOS-WSL-Installer para automatizar a implantação de ambiente de análise no WSL2 com GUI e XRDP.

  • Gestão de infraestrutura privada ARM com Raspberry Pi/CasaOS, monitoramento e DNS Sinkholing via Pi-hole.

Projects(6)

Sentinel Forge
  • Electron
  • React
  • Vite
  • Node.js
  • EDR
  • Supply Chain Security
https://github.com/chavatte/sentinel-forge

Tactical EDR & Supply Chain Defense Toolkit.

  • Desktop security toolkit focused on tactical detection, response, and supply-chain defense.

Sentinel Git-OPS
  • Node.js
  • GitOps
  • Security Operations
  • Windows
  • Linux
https://github.com/chavatte/sentinel-git-ops

Plataforma/CLI de operações Git com auditoria, gestão de branches e controles de resposta.

  • Auditoria operacional e branch management para Windows/Linux.

  • Versão de referência do currículo: 2.3.0.

Sentinel OPS
  • Node.js
  • SQLite
  • Docker
  • OSV
  • Supply Chain Security
  • SecOps
https://chavatte.vercel.app/projects/sentinel-ops

Dashboard de segurança de dependências Node.js e supply chain, com análise de risco e automação de governança.

  • Integração com OSV.

  • Motor SQLite.

  • Threat Analytics e automação de governança.

Enoch Engine API
  • Node.js
  • Express
  • PostgreSQL
  • Docker
  • API Security
https://github.com/chavatte/Enoch-Engine

Boilerplate backend production-grade orientado a segurança, autenticação, PostgreSQL e Docker.

  • Anti-DoS.

  • Token Versioning.

  • Graceful Shutdown.

  • Uploads em stream.

  • Multi-Schema via Docker.

Enoch Engine SOC
  • Node.js
  • Threat Intelligence
  • Phishing
  • Safe Browsing
https://chavatte.vercel.app/projects/enoch-soc

Pipeline de inteligência e triagem de phishing / threat intelligence.

ParrotOS-WSL-Installer
  • WSL2
  • Parrot OS
  • Automation
  • Linux
  • XRDP
https://github.com/chavatte/ParrotOS-WSL-Installer

Automação de implantação de ambiente de análise no WSL2 com GUI e XRDP.

Education(3)

Programa de Formação Cibersegurança
Hackers do Bem
  • Residência em Red Team
  • Especialização em Red Team
  • Formação Fundamental
  • Formação Básica
Extensão Universitária Análise de Market Share (Android x iOS)
UFSCar
Web Full Stack Degree Desenvolvimento Web Full Stack
Let's Code / Ada

Certificates(17)

CyberOps Associate
Cisco
Network Defense
Cisco
CCNA1: Introduction to Networks
Cisco
Cybersecurity Essentials
Cisco
Endpoint Security
Cisco
Red Team Residency & Specialization
Hackers do Bem / MCTI / SENAI
Fundamental Level
Hackers do Bem / MCTI / SENAI
Basic Level
Hackers do Bem / MCTI / SENAI
Azure AI Fundamentals
Microsoft
AI Agents
Microsoft / Training Programs
Generative AI Fundamentals / Claude 3
Training Programs
Java Cloud Native
Bradesco / DIO
Backend with Java
Santander / DIO
Python AI
Vivo / DIO
Backend APIs
freeCodeCamp
JavaScript
freeCodeCamp
Responsive Web Design
freeCodeCamp

Publications(5)

PoC - Android Open Resolver
in Chavatte Security

Pesquisa ofensiva sobre exploração de DNS, Open Resolvers e stress testing; destaque de 1.500 QPS.

Docker Engine AuthZ Bypass: Anatomia do CVE-2026-34040 e Root Escalation
in Chavatte Security

Pesquisa técnica em segurança de containers.

eBPF Rootkits: O Lado Sombrio da Observabilidade no Kubernetes (PoC)
in Chavatte Security

Pesquisa técnica em Cloud Security.

Wasm-Jacking: Evasão de SAST e Malwares Ocultos em Dependências Node.js
in Chavatte Security

Pesquisa em Supply Chain Security.

AI PR Reviewer Hijacking: Prompt Injection Direto na Esteira (CVE-2026-40112)
in Chavatte Security

Pesquisa em AI Security.