/ about

A student who breaks things
for a grade.

Offensive security student at Hogeschool Utrecht. 24 years old. Active Directory, Linux, and web. Whatever the box asks for.

My main platform is HackTheBox: 50+ machines across Easy → Insane. I write a machine up after it retires, because explaining the chain is where the learning actually sticks.

On the Windows side: Kerberos abuse (AS-REP, Kerberoast, delegation chains), BloodHound path-finding, NTLM relay, and certificate services abuse. I run a Server 2022 DC and two workstations at home to rebuild the same attacks outside the platform.

On Linux: privesc through weak services, SUID chains, misconfigured cron. On the web: SQLi, SSRF, auth bypass, chained logic bugs, manual-first with Burp.

I glue my recon together with Python: nmap, ffuf, gobuster piped into a single report template. Currently grinding CCNA because the best attackers actually understand the network they're living in. Next on the cert list: CJCA and CPTS.

windows
Active Directory
Kerberos abuse, BloodHound paths, NTLM relay, certificate services, full domain compromise.
web
Web Exploitation
SQLi, SSRF, auth bypass, and chained logic flaws, manual-first with Burp Suite.
privesc
Privilege Escalation
Linux + Windows: weak services, SUID chains, DLL hijack, token impersonation.
creds
Password Attacks
Hashcat rules, Responder, Pass-the-Hash, credential hunting on AD.
tooling
Python Automation
Recon orchestration: nmap + ffuf + gobuster into a single pipeline.
network
Networking
CCNA in progress: routing, VLANs, ACLs, the plumbing under every box.
Copied