AVAILABLE FOR PROJECTS

Rafael Cavalcanti da Silva
Fullstack Developer & Security Specialist

Immersed in technology since age 10 and working professionally since 16. With 22+ years of career, I develop high-impact software. Founder of xpusher.net and wsocket.io. From projects for government, international orgs and industry to complex SaaS platforms, multi-language SDKs and vulnerability research — I deliver end-to-end solutions.

name Rafael Cavalcanti da Silva birth September 13, 1988 — Brasília, DF experience 22+ years commercial (since 2004) · 28+ years in tech (since 1998) focus Fullstack Development, SEO, Information Security, SDK Engineering languages 16+ (Python, Go, TypeScript, Rust, C, Dart, Java, Kotlin, C#, PHP…) first projects hoststart.com.br · ritmosbsb.com (2004)
22+
Years of Experience
16+
Languages
16
Published SDKs
30+
Projects
9
Institutional Clients

Blog

· 45 min read

Breaking 9 layers of DexProtector: Real-world reverse engineering of an Android banking app

Advanced reverse engineering analysis of a mobile banking app protected by DexProtector with 9 layers: encrypted DEX, ~2000 enc!5016 strings, JNI dispatch with 148 overloads, dynamic RegisterNatives, TEA-like stream cipher, ARM64 emulation with Unicorn, memory-only .so dump, ALICE anti-fraud bypass — all documented with real code and results.

#reverse-engineering#frida#android#jni#dexprotector#unicorn#arm64#capstone#banking#security#cyber-security#pentesting
· 25 min read

SEO Case Study: From zero to Google's top — Part 1: Diagnosis, tech stack and first steps

Real-time series documenting the process of ranking 'Rafael Cavalcanti da Silva', 'rafael cavalcanti', 'rafael' and 'root' on Google — using Astro, Nginx, Google Analytics 4, Search Console and advanced technical SEO techniques.

#seo#google#astro#nginx#analytics#case-study#ranking
· 30 min read

Real-world Linux Server Hardening: 14 layers I apply in production with automation code

Advanced Linux hardening guide based on real infrastructure: SSH hardening + fail2ban + UFW + kernel sysctl + auditd + systemd sandboxing + nginx auto-fix + Redis bind + MongoDB auth + Postfix secure relay + automated backup with Google Drive + orchestrated restore via Go + Conky monitoring — all with production scripts and configs.

#security#cyber-security#linux#hardening#devops#defensive#nginx#systemd#automation
View all articles →