I have a relentless passion and unbridled curiosity for all things offensive security. Honing my skill set is a craft that takes time, discipline, learning from mistakes, and a good sense of humor.
I document every investigation and challenge, including the occasional wrong turn. I trust my intuition and innate pattern-recognition skills, and I am never afraid to ask questions. Every solve equips me with new tools, techniques, and another anomaly to detect if it resurfaces.
The work spans web application exploitation, Active Directory, Linux and Windows privilege escalation, binary exploitation and reverse engineering, network and OT security, and AI and machine learning security. It has also introduced me to a remarkable number of deeply cursed applications, all of which I find great joy in learning to navigate. I genuinely love what I do. I never run out of questions.
Custom tools and scripts built during these engagements: Scripts →
Featured investigations
- Operation Endgame: Active Directory attack chain using Kerberoasting, credential spraying, BloodHound, targeted Kerberoasting, and SMB execution to SYSTEM.
- Sequence: Stored XSS, cookie theft, CSRF privilege escalation, parameter manipulation, web-shell upload, and Docker socket abuse to host root.
- Voyage: Joomla API credential disclosure, internal discovery, SSH tunneling, insecure pickle deserialization, and a Linux capability escape from containers to the host.
- Gatekeeper: Windows buffer-overflow development, local exploit validation, credential extraction, and SMB execution to SYSTEM.
- IronHold: Spring Boot source analysis, SQL injection, role overposting, and Java deserialization leading to remote code execution.
- ContAInment: PCAP analysis, prompt-injection reconstruction, LLM jailbreak analysis, and encrypted evidence recovery.
Authorized training labs
- Sliver C2, Lateral Movement, and Persistence: Authorized Red Siege lab work using Sliver to move laterally into SQL01, gain
SYSTEMaccess, establish service and WMI persistence, and clean up afterward.
Cyber Apocalypse 2026: The Salt Crown
Completed Hack The Box Cyber Apocalypse writeups:
- The Emptiness Machine: Two profoundly cursed
scanf()calls led to a FILE-structure attack hiding inside the process's standard streams. - The Raven That Landed Twice: OSINT investigation. The raven only landed twice in the paperwork.
- Mement0: Recovered a deleted malicious Claude skill, traced its persistent project instructions, and reconstructed encrypted payload fragments from Git history.
- Assay: Cloned a black-box classifier, transferred a constrained adversarial example, recovered a hidden backdoor specification, and forged a composite model.
- The Cinder Engine: Recovered a custom virtual machine from a stripped ARM64 binary, built a Python disassembler and emulator, and inverted its eight-round validation transform.
- CorpSyncAudit: Reversed a compromised Windows audit client and reconstructed a 396-byte x64 payload from fabricated timestamp and region records.
- Archonyx: Chained an authenticated bot, query-parser differential, unsafe ZIP extraction, database replacement, and local Less plugin into server-side execution.
- Signetry: Chained token forgery, stored client-side execution, Apache type-map subrequests, a privileged review bot, Java deserialization, and a race condition to reach code execution.
- Overstrike: Reversed a Godot C# mobile application, proved its legitimate seal state unreachable, inverted its transformation, and decrypted the protected registry.
Writeup index
The collection below is organized by the system or attack surface being examined. Several investigations cross more than one category; each appears once here.
Active Directory and Windows
- Operation Endgame
- Ledger
- Active Directory: Lateral Movement
- Relevant
- Steel Mountain
- Alfred
- HackPark
- Windows Privilege Escalation
- Stored Credentials
- Scheduled Task Abuse
- Service Executable Permissions
- Unquoted Service Path
- Insecure Service DACL
Web applications and APIs
- Lookup
- Cheese
- Sisterhood of the Traveling Packets
- Daily Bugle
- Decryptify
- Jack
- Injects
- CyberCrafted
- What's Your Name
- Surfer
- CAPTCHApocolypse
- Sequence
- Padelify
- Farewell
- Operation Coldstart
- Game Zone
- Skynet
- Internal
- Recruit
- IronHold
- Upload Vulnerabilities
- Burp Suite
Linux, containers, and privilege escalation
- Valley
- Matryoshka
- Voyage
- Kenobi
- Overpass 2: Hacked
- KOTH: Shrek
- Linux Privilege Escalation
- Kernel Exploit: CVE-2015-1328
- Sudo Misconfiguration
- SUID Abuse: base64
- Capabilities: vim cap_setuid
- Cron Job Hijack
- PATH Hijacking
- NFS no_root_squash