HTB - Bedside
Hack The Box write-up with exploitation notes and lessons learned.
$ whoami
Offensive security
I break down real-world security problems through hands-on testing, research, and practical write-ups.
Never stop learning, because life never stops teaching.
About
Cyber security is best understood by doing, not just reading. I learn by experimenting with real-world attack paths and lab environments to understand how systems fail and how they can be secured.
I enjoy breaking things only after understanding how they work. That curiosity drives my approach to penetration testing, red teaming, and knowledge sharing.
SEGi University – Diploma in Computer Studies
Skills
Certifications
Write-ups
Hack The Box write-up with exploitation notes and lessons learned.
Hack The Box write-up with exploitation notes and lessons learned.
Hack The Box notes focused on practical attack path thinking.
Request-level exploitation notes for React Server Components RCE testing.
Troubleshooting notes for Burp Suite DNS handling and match-replace behavior.
Using LLM-assisted workflows to accelerate source code review and vulnerability discovery.
A practical SSH and EC2 workflow for proxying client VDI traffic into Burp Suite Pro.
Active Directory escalation notes from Kerberos ticketing and hash-dump edge cases.
DNS exfiltration testing in restricted network conditions.
Pivoting through Mythic C2 and proxychains in an assume-breach style lab.
Hands-on AD security testing with SpicyAD, Kerberoasting, delegation, and enumeration.
Notes on using AI assistance while enumerating Active Directory environments.
Remote access notes for homelab connectivity using Tailscale.
Static and behavioral notes from Android banking malware analysis.
Android exported activity testing and root detection bypass observations.
CVE / Research
A structured home for CVE notes, affected products, vulnerability classes, and references.
OS Command Injection, Arbitrary File Upload, SQL Injection
OS Command Injection, SSRF, Directory Enumeration, Reflected XSS
Arbitrary File Upload, Stored XSS
Server-Side Request Forgery
Arbitrary File Upload, Reflected Cross-Site Scripting
OS Command Injection, Reflected Cross-Site Scripting
Server-Side Request Forgery
Contact
Available for focused security assessments, research collaboration, and advisory work.