Network
penetration testing, Active Directory exploitation (Kerberoasting, AS-REP
roasting, delegation attacks, RBCD, NTLM relay, BloodHound path analysis), web
application testing (OWASP Top 10, SQLi, XSS, SSRF, authentication bypass),
password attacks, privilege escalation (Windows and Linux), post-exploitation,
lateral movement.
Burp Suite, Nmap, Metasploit, BloodHound, CrackMapExec/NetExec, Impacket, Responder,
Mimikatz, Nessus, Nikto, ffuf, SQLMap, Hashcat, Wireshark, Kali Linux
Commercial-grade
pentest reports with executive summaries, proof-of-concept documentation, CVSS
v3.1 scoring, and remediation roadmaps. Comfortable briefing both technical and
non-technical stakeholders.
Handle: n0ah77
| Silver Tier | 550+ machines compromised
Competed across
Windows, Linux, and Active Directory domains. Focused heavily on AD attack
chains including unconstrained delegation, constrained delegation, RBCD,
WriteSPN-based Kerberoasting, and the BadSuccessor/dMSA technique.
Some (but not all) of the projects I have completed include: