I have a relentless passion and unbridled curiosity for all things offensive security. Honing my skill set is a craft that takes time, discipline, learning from mistakes, and a good sense of humor.

I document every investigation and challenge, including the occasional wrong turn. I trust my intuition and innate pattern-recognition skills, and I am never afraid to ask questions. Every solve equips me with new tools, techniques, and another anomaly to detect if it resurfaces.

The work spans web application exploitation, Active Directory, Linux and Windows privilege escalation, binary exploitation and reverse engineering, network and OT security, and AI and machine learning security. It has also introduced me to a remarkable number of deeply cursed applications, all of which I find great joy in learning to navigate. I genuinely love what I do. I never run out of questions.

Custom tools and scripts built during these engagements: Scripts →

Featured investigations

  • Operation Endgame: Active Directory attack chain using Kerberoasting, credential spraying, BloodHound, targeted Kerberoasting, and SMB execution to SYSTEM.
  • Sequence: Stored XSS, cookie theft, CSRF privilege escalation, parameter manipulation, web-shell upload, and Docker socket abuse to host root.
  • Voyage: Joomla API credential disclosure, internal discovery, SSH tunneling, insecure pickle deserialization, and a Linux capability escape from containers to the host.
  • Gatekeeper: Windows buffer-overflow development, local exploit validation, credential extraction, and SMB execution to SYSTEM.
  • IronHold: Spring Boot source analysis, SQL injection, role overposting, and Java deserialization leading to remote code execution.
  • ContAInment: PCAP analysis, prompt-injection reconstruction, LLM jailbreak analysis, and encrypted evidence recovery.

Authorized training labs

Cyber Apocalypse 2026: The Salt Crown

Completed Hack The Box Cyber Apocalypse writeups:

  • The Emptiness Machine: Two profoundly cursed scanf() calls led to a FILE-structure attack hiding inside the process's standard streams.
  • The Raven That Landed Twice: OSINT investigation. The raven only landed twice in the paperwork.
  • Mement0: Recovered a deleted malicious Claude skill, traced its persistent project instructions, and reconstructed encrypted payload fragments from Git history.
  • Assay: Cloned a black-box classifier, transferred a constrained adversarial example, recovered a hidden backdoor specification, and forged a composite model.
  • The Cinder Engine: Recovered a custom virtual machine from a stripped ARM64 binary, built a Python disassembler and emulator, and inverted its eight-round validation transform.
  • CorpSyncAudit: Reversed a compromised Windows audit client and reconstructed a 396-byte x64 payload from fabricated timestamp and region records.
  • Archonyx: Chained an authenticated bot, query-parser differential, unsafe ZIP extraction, database replacement, and local Less plugin into server-side execution.
  • Signetry: Chained token forgery, stored client-side execution, Apache type-map subrequests, a privileged review bot, Java deserialization, and a race condition to reach code execution.
  • Overstrike: Reversed a Godot C# mobile application, proved its legitimate seal state unreachable, inverted its transformation, and decrypted the protected registry.

Writeup index

The collection below is organized by the system or attack surface being examined. Several investigations cross more than one category; each appears once here.

Active Directory and Windows

Web applications and APIs

Linux, containers, and privilege escalation

Binary exploitation, reversing, and cryptography

AI and machine learning security

Network, OT, cloud, and post-exploitation