Artifacts and credentials. Positioning and background on the Home page.
Artifacts
- offsec-scripts — 15+ field tools for enumeration, credential triage, and privilege-escalation checks, written in Bash and Python. Each ships with a dedicated unit-test harness covering shell-semantics and parsing edge cases. offsec-scripts on GitHub.
- offsec-playbooks — a structured penetration-testing methodology vault: 26+ Linux and Windows privilege-escalation techniques, exploit walkthroughs (Dirty COW, Exim
perl_startup, MS15-051, MS16-032), a full web-application testing workflow, and credential-extraction, hashing, and encoding references. offsec-playbooks on GitHub. - appsec-lab — OWASP Top 10 (2025)-mapped case studies in PHP and Python. Each keeps a vulnerable-baseline branch and a regression-tested remediation on main, following a threat → repro → impact → fix → prevention structure. Three studies live: A01 broken access control (IDOR), A02 security misconfiguration, A03 supply-chain. appsec-lab on GitHub.
- CTF write-ups — TryHackMe walkthroughs covering enumeration, exploitation, and privilege escalation, written as reproducible operator notes. View the write-ups.
- This website — hand-built static site: no themes, templates, or generators. Source on GitHub.
Training & standing
- OSCP+ — in preparation.
- Top 3% on TryHackMe — 144 rooms completed, rank 0xA. Profile.
Certifications
- Certificate of Cloud Security Knowledge (CCSK v4) — Cloud Security Alliance, 2022.
- Zend Certified PHP Engineer — Zend, 2022.
- BCS Level 4 Diploma in Software Development Methodologies — British Computer Society, 2020.