A student who breaks things
for a grade.
Offensive security student at Hogeschool Utrecht. 24 years old. Active Directory, Linux, and web. Whatever the box asks for.
My main platform is HackTheBox: 50+ machines across Easy → Insane. I write a machine up after it retires, because explaining the chain is where the learning actually sticks.
On the Windows side: Kerberos abuse (AS-REP, Kerberoast, delegation chains), BloodHound path-finding, NTLM relay, and certificate services abuse. I run a Server 2022 DC and two workstations at home to rebuild the same attacks outside the platform.
On Linux: privesc through weak services, SUID chains, misconfigured cron. On the web: SQLi, SSRF, auth bypass, chained logic bugs, manual-first with Burp.
I glue my recon together with Python: nmap, ffuf, gobuster piped into a single report template. Currently grinding CCNA because the best attackers actually understand the network they're living in. Next on the cert list: CJCA and CPTS.