How I got here

I do not come from a computer science degree or a master’s. I arrived at security the long way round, which is breaking things at home, working out why they broke, and putting them back together better. Everything I know comes from reading documentation, building labs, and getting it wrong plenty of times in private before touching anything that mattered.

Being self taught has one obvious problem: nobody signs a piece of paper saying you can do the job. The answer I settled on is to publish the work. If someone wants to know whether I can move through a Windows domain, they do not have to take my word for it, they can read a full writeup and judge for themselves.

What I do now

I single handedly run the technical operations of a virtual reality entertainment venue. That means the network, the systems, the point of sale, the equipment in the rooms, and whatever breaks on a Saturday afternoon with a full house. It is not a lab environment, it is a real business with customers inside, and it taught me something no course covers: a security recommendation you cannot apply without stopping the business from taking money is worth nothing.

That is a large part of why Domain Security exists. I know the side that receives the report, not just the side that writes it.

Published work

Hack The Box writeups. I publish full solutions for retired machines, mostly Active Directory and some Linux. They are not summaries: they run from initial reconnaissance to full compromise, with the commands, the reasoning, and the dead ends that led nowhere. They are all on the blog.

A real security audit. A direct engagement for a company. Complete work, with a technical report and an executive report delivered to the client. The content of an audit is confidential and belongs to whoever commissioned it, so I do not publish it. To see how I write a report, the sample ones are in the portfolio.

What I am studying

Right now I am working towards the CompTIA Security+ certification. I care about it less for the certificate than for what it forces me to organise: covering the defensive and governance side systematically, which is easy to leave half done when you learn on your own and find attacking more fun.

Where I am heading

I want to specialise in Active Directory and red team work. It is where I have spent the most time, where the problem grips me most, and where I think I can genuinely contribute: most Spanish small businesses with more than ten employees are running a Windows domain set up years ago, inherited, that nobody has ever reviewed properly.

Domain Security is young and I am not going to pretend otherwise. I do not have a long client list and I am not going to invent one. What I have is public technical work you can check, a real audit delivered, and the habit of saying no when something is beyond me.