Archangel — Full Attack Chain
Chained an LFI to unauthenticated RCE via log poisoning, then escalated to root through cron abuse and PATH hijacking.
bb@sec:~$ whoami
Junior Penetration Tester // Offensive Security
I break into web apps, networks, and APIs the way an attacker would — then turn every finding into clear, reproducible reporting that helps teams fix what matters. Driven to secure the digital world by understanding threats before they strike.
Available for engagements & full-time rolesI'm an offensive security practitioner and Junior Penetration Tester with hands-on experience running web application and network security assessments inside a PTaaS consulting environment. Across 5 client engagements I identified 73 vulnerabilities — including high-impact IDOR, XSS, and Arbitrary File Upload findings — each documented with proof-of-concept exploits, CVSS ratings, and actionable remediation. I was promoted from intern to Junior Penetration Tester on the strength of consistent, high-quality findings and professional reporting.
+ specialized findings: CSV/XLSX formula injection · insecure password-recovery workflow · username enumeration
Tools, languages, and methodologies I use across the full assessment lifecycle — recon → exploitation → privilege escalation → reporting.
Selected hands-on work — from client-style methodology to CTF-grade exploitation. Click a card for the attack chain; full reports open as PDFs. All testing performed with explicit authorization.
Chained an LFI to unauthenticated RCE via log poisoning, then escalated to root through cron abuse and PATH hijacking.
Enumerated a Windows domain, abused AS-REP Roasting to recover creds, and pivoted to domain compromise via DCSync + Pass-the-Hash.
Assessed a Windows enterprise network behind pfSense — white-box & black-box — then hardened policy and re-scanned to confirm fixes.
Enumerated ports, services, and misconfigurations from Kali; triaged critical/high/medium findings and mapped each to concrete remediation.
Tested REST APIs for broken object-level authorization, excessive data exposure, and weak access control via JWT manipulation and object-reference tampering.
Intercepted login requests with Burp, automated credential guessing with Hydra, and documented defenses: MFA, lockout, rate limiting.
Built a dropper, delivered via phishing, executed payload to encrypt files, then recovered with a private key — mapping the full lifecycle end to end.
Performed SOC-style alert triage and log analysis on simulated SIEM data; identified IOCs including suspicious IP activity and authentication abuse.
Represented Syracuse University in the NCAE Cyber Games regional round — a national, team-based cyber-defense competition, hardening and defending live services against an active red team.
Implemented symmetric & asymmetric encryption with OpenSSL, GPG/Kleopatra, and WinSCP to encrypt, sign, transfer, and verify data across systems.
Open to full-time offensive security roles, internships, and authorized security assessments. Let's talk.
Ethical note: I only test assets with explicit authorization or within approved programs.