Intrusion writeups
Complete solutions for retired Hack The Box machines, start to finish: reconnaissance, initial access, lateral movement and escalation to full control. They include the commands, the reasoning behind each decision, and the attempts that failed, which are usually the most useful part.
Most of them are Windows environments with Active Directory, which is where I am focusing my specialisation, and there are Linux machines too.
- HTB: Certified · from WriteOwner to Domain Admin by chaining ACLs, Shadow Credentials and ESC9
- HTB: Cascade · from an anonymous LDAP dump to Domain Admin via the AD Recycle Bin
- HTB: Previse · from a broken PHP redirect to root via command injection
- HTB: Monteverde · leaked Azure AD Connect credentials to Domain Admin
- HTB: Resolute · from anonymous RPC to Domain Admin via DnsAdmins
Sample pentest reports
For each of these machines I wrote the full report, in the same format I deliver on a real engagement. They are there so you can see how I write up a finding, how I score it with CVSS, and what the deliverable looks like before you commission anything.
Security audit for a company
A direct engagement for a company, run end to end: scope agreement, offensive testing, configuration review, and delivery of a technical report alongside an executive report for management.
It is the work I am most satisfied with and, by its nature, the only piece I cannot show. The content of an audit is confidential and belongs to whoever commissioned it, so it is not published in full or in summary.
If you want to see what the deliverable looks like, the sample reports above follow exactly the same structure: the same finding format, the same CVSS scoring and the same pairing of executive and technical report. What changes on a real engagement is the scope, not how I work or how I document it.
On the legality of this testing
All the technical content on this site comes from authorised lab environments, specifically retired machines on the Hack The Box platform, or from professional engagements carried out under prior written authorisation from the owner of the systems. None of the published techniques has been run against third party systems without permission.