0x74shelby
SECURITY_ENGINEER

I break into networks, web apps, and Active Directory forests for a living, then write the report that helps the blue team fix it. CEH and CPTS certified. Red team, pentesting, and the occasional late-night CTF grind.

0x74shelby - Security Engineer
Active Objective
HTB: OMNISCIENT

Capabilities

security

Penetration Testing

Three years in, I've lost count of the apps, networks, and AD forests I've chewed through. I chase down OWASP Top 10 issues: injection flaws, broken access control, misconfigurations, against internal and external client environments. My job is simple. Find what the attacker would find, before they do, then prove it with a repro, not a guess.

Web Apps Active Directory Network Security OWASP Top 10
track_changes

Red Teaming

I play the threat actor so your SOC doesn't have to meet a real one cold. BloodHound maps the graph, then Impacket and Mimikatz do the dirty work: Kerberoasting, AS-REP roasting, weak trust relationships, excessive privilege, all the way to domain compromise. The goal isn't just a flag. It's figuring out exactly where the defence blinks.

Privilege Escalation Pivoting OSINT Kerberos Attacks

Arsenal

  • Burp Suite Pro
  • Metasploit
  • Nmap / Nessus
  • BloodHound
  • Wireshark
  • SQLMap / Ffuf
  • CrackMapExec
  • Impacket Suite
  • Hashcat / John
  • Evil-WinRM
HTB Certified Penetration Testing Specialist (CPTS) badge CPTS
EC-Council Certified Ethical Hacker (CEH) logo CEH

CPTS & CEH CERTIFIED

HTB's CPTS and EC-Council's CEH, backed by three-plus years of hands-on engagements. I don't treat certs as trophies. They're just proof I've been tested on the same stuff I claim to know.

Frameworks, Standards & Other Ground I Cover

OWASP PTES OSSTMM MITRE ATT&CK NIST CSF Cyber Kill Chain CVSS Scoring Cryptography Wireless / Wi-Fi Security Cloud Security (AWS / Azure) Bug Bounty Methodology Client Debriefs & Reporting
Blinders - Black Box Pentest
Black Box Penetration Testing

Blinders

Zero access, zero hints. I started with a company name and an IP range. OSINT turned up a reused password, credential stuffing got me a shell, and from there it was a short walk to root. Honestly, the weakest link was never technical. It was reuse.

terminal Black Box
hub Medium
description View Report
Demon - Grey Box Pentest
Grey Box Penetration Testing

Demon

Grey box, the closest thing to modelling an insider threat. Vhost enum was the chef's kiss here; a hidden Jenkins instance was quietly screaming for attention. A sloppy sudo rule did the rest. Root in under a day.

Read Report arrow_forward
KGF - White Box Pentest
White Box Penetration Testing

KGF

White box. I had the source, the network map, the works, and it still took real work. Two segmented environments, a careful pivot, SNMP leaking what it shouldn't, and eventually root on both. My favourite engagement so far.

terminal White Box
hub Hard
description View Report

Intel Feed

What I'm reading, writing & pwning lately