Here is my PGP public key for my Git email.
I’m an offensive security practitioner, primarily training on Hack The Box (see my profile for stats and progress tracking). On the offensive side my favourites are:
- AD/LDAP exploitation: BloodHound, Kerberos abuse (AS-REP roasting, Kerberoasting, constrained/unconstrained delegation), ACL/GPO misconfig, certificate service attacks, lateral movement, and privilege escalation in enterprise environments.
- C2 frameworks: Mythic, Sliver
- Binary exploitation and RE: vulnerability discovery and exploit development across a wide variety of architectures (mainly AMD64, but also a handful of RISC architectures, mainly ARM and RISC-V), modern mitigations (ASLR, NX, PIE, canaries, RELRO) and bypasses, ROP chaining, and binary debugging and disassembly/RE (pwndbg and Ghidra).
- Web exploitation: authentication/authorization flaws, injection classes (SQLi/NoSQLi/command injection), SSRF/file inclusion/deserialization, BurpSuite.
- Wireless and network offensive operations: Wi-Fi security (WPA2/WPA3, rogue AP/evil-twin), internal network service exploitation (SMB/WinRM/RPC/LDAP), and traffic analysis.
On the defensive side:
- Reverse engineering (Ghidra, mainly): static analysis, function and type recovery, decompilation.
- Malware and exploit analysis: unpacking, behavioral analysis, finding IOCs and persistence, and mapping to ATT&CK.
I also do some programming in Rust, and a lot of tinkering around with x86, RISC-V, and Raspberry Pis when I get a chance.
Below are some of the rarest HTB badges I've achieved. I have a lot more, of course, but these are the hardest, most interesting ones I have completed, in no particular order. All these machines and challenges are Insane level difficulty. Click on any of the images to view them on my HTB profile and see the rarities for yourself:








