Security Through Adversarial Thinking
I use offensive-security labs to study how systems fail in practice: misconfiguration, weak trust boundaries, authentication flaws, privilege escalation, identity weaknesses, application vulnerabilities, and the interaction between operating systems, networks, and services.
The goal isn’t simply to complete a machine. It’s to understand why the vulnerability existed, how the attack path developed, and what could have been designed differently to prevent it.
That perspective directly informs how I approach cloud, infrastructure, identity, automation, and security architecture.
Offensive security is one of the ways I pressure-test my understanding of defensive architecture.
Windows & Identity
Active Directory, authentication, privilege escalation, PowerShell, Windows services, and identity attack paths.
Linux & Infrastructure
Services, permissions, applications, network exposure, local privilege escalation, and system misconfiguration.
Advanced Labs
Longer multi-system attack paths, chained vulnerabilities, lateral movement, and complex trust relationships.
What This Research Demonstrates
Cross-Domain Troubleshooting
Working across Windows, Linux, networking, identity, applications, services, and infrastructure rather than treating each technology as an isolated system.
Security Analysis
Examining authentication, privilege boundaries, service exposure, protocol behavior, insecure configurations, and application weaknesses.
Adversarial Thinking
Understanding how systems can be abused so defensive architecture can account for real attack paths rather than idealized assumptions.
Technical Depth
Following attack paths from enumeration and initial access through privilege escalation, credential discovery, and system compromise.
Documentation
Turning technical investigation into repeatable walkthroughs that explain the path, techniques, and underlying failure conditions.
Defensive Architecture
Using lessons from offensive research to identify where stronger identity controls, trust boundaries, configuration, and monitoring could prevent or limit compromise.
Hack The Box Writeups
The writeups below cover retired Hack The Box systems and labs only.
They are retained as a technical research library and as a record of hands-on work across Windows, Linux, identity, applications, networking, and security.
Endgame Labs
These labs involve longer, multi-stage attack paths and are useful for studying how individual weaknesses can combine into broader system compromise.
Unix / Linux Machines
Easy Machines 30 writeups
Medium Machines 25 writeups
Hard Machines 13 writeups
Windows Machines
Easy Machines 15 writeups
Medium Machines 14 writeups
Insane Machines 3 writeups
Legacy HTB Material
Some older HTB material is preserved here for historical reference.
Beyond the Labs
Security research is one part of a broader body of work covering cloud architecture, infrastructure engineering, automation, secure systems, identity, and custom tooling.
Technical Case Studies
Architecture and engineering work covering real-world infrastructure, security, automation, and operational problems.
Projects & Tooling
Custom software, security tooling, automation, and open-source projects.
Personal GitHub → OsbornePro GitHub → NovaKey → RDAP-CLI → EncrypIT Documentation → BTPS Security Pacakge → PowerShell Gallery →
Technical Content & Credentials
Contact
For professional inquiries: