Real targets. Real exploits. Real reports. This is what I can break and how I break it.
Real engagements. Real exploits. Real reports.
Black-box penetration test against OWASP Juice Shop, an intentionally vulnerable Node.js e-commerce application. The assessment identified 9 vulnerabilities across 7 OWASP Top 10 (2021) categories, including two Critical-severity issues enabling complete session takeover.
End-to-end forensic investigation of a compromised Linux web server across six evidence domains. Every step was reconstructed from raw evidence: system logs, a RAM dump, a packet capture, disk images, and a custom ELF malware sample, producing a complete 12-event attack timeline mapped to 10 MITRE ATT&CK techniques.
Two-part tool built directly from the CyberDefenders Linux Breach Investigation CTF. dfir-triage.sh runs all six forensic modules in sequence: log analysis, memory forensics, network forensics, disk forensics, malware triage, and timeline correlation.
Active network pentest lab, custom Python offensive tooling, and a red-team scenario. Each will follow the same attack-driven format: target, exploit chain, impact, evidence.
HackTheBox machine writeups and DFIR challenge series, documenting methodology, tools, and findings. 14 HTB machine write-ups live: Cicada, Heist, Return, Timelapse, Support, Active, Sauna, Forest, Cap, Lame, Shocker, Bashed, Nibbles, Access. DFIR Challenge Series: all 6 write-ups live.
Documented HTB machine compromises: full attack chains, techniques, and lessons learned from every root.
Exploited an IDOR vulnerability to access another user's packet capture, extracted FTP plaintext credentials via Wireshark, reused those credentials for SSH access, then escalated to root via Linux capabilities (cap_setuid) on Python 3.8.
CVE-2007-2447 exploited via the Metasploit usermap_script module: the Samba username map script option passes the authentication username to /bin/sh without sanitizing shell metacharacters.
CVE-2014-6271 (Shellshock) exploited via the User-Agent header: Apache passes HTTP headers as environment variables to CGI scripts running on a vulnerable bash version.
The /scripts/ directory is owned by scriptmanager but test.txt is root-owned with a fresh timestamp: cron is running test.py as root.
Anonymous FTP exposes two files in separate directories: a Microsoft Access database and a password-protected zip archive.
The My Image plugin accepts PHP file uploads despite throwing image processing errors, the file hits disk regardless.
Enumerated the full domain user list via RPC null session without credentials, identified svc-alfresco with pre-auth disabled and obtained its AS-REP hash, cracked the hash offline with Hashcat, then used BloodHound to trace a four-hop nested group path from svc-alfresco through Account Operators to WriteDACL on HTB.LOCAL.
An anonymous SMB share exposes a default password in an HR notice.
A ticket attachment contained a Cisco router configuration with three password entries.
The settings page sends LDAP credentials to any server address configured on the form.
Cracked the zip password (supremelegacy) and PFX password (thuglegacy) independently with john, extracted the certificate and key with openssl, and authenticated to WinRM over HTTPS on port 5986 as legacyy.
A custom .NET binary on the share contained XOR-encoded LDAP credentials, recovered via monodis IL decompilation and a Python decode script.
Anonymous SMB access to a non-standard Replication share exposed Groups.xml containing a GPP cpassword.
Harvested six employee names from the public-facing website to build a username wordlist, identified fsmith with pre-authentication disabled and captured the AS-REP hash, cracked it offline with Hashcat, then used WinPEAS to find AutoLogon registry credentials for svc_loanmgr.
Each challenge adds a new evidence domain: system logs, RAM dump, packet capture, disk images, malware sample, and final timeline synthesis.
Documenting every machine rooted on HackTheBox. Write-ups added as completed.
Industry-recognised credentials validating expertise in cybersecurity, compliance, and AI governance. Click any badge to verify on Credly.
Courses, workshops, and hands-on training spanning offensive security, cloud infrastructure, and development. Click any card to view the certificate.
The pipeline is loaded. These sections are actively being built, so check back soon.
Step-by-step walkthroughs of HackTheBox machines, documenting exploit chains, methodology, and post-exploitation techniques. 14 write-ups live: Cicada, Heist, Return, Timelapse, Support, Active, Sauna, Forest, Cap, Lame, Shocker, Bashed, Nibbles, Access.
View Writeups ↑Custom Python-based offensive and defensive tooling: recon automation, payload generators, SIEM integrations, and network scanning utilities.
In DevelopmentStructured lab environments covering Active Directory attack chains, network pivoting, malware analysis sandbox walkthroughs, and detection engineering labs.
PlannedWhether it's a penetration testing engagement, a security consultation, or a collaboration, I'm ready. Let's talk.