xomnibot · Security Researcher & Systems Enthusiast
Cybersecurity Whiz & Open Source Builder
To make technical cybersecurity research fun, accessible, and 100% practical through code, CTF teardowns, and open-source software.
- [1] recon: nmap -sV web01 → 80/tcp open
- [2] exploit: command injection → shell as www-data
- [3] pivot: creds in config → app01
- [4] kerberoast: svc_sql hash cracked → db01
- [5] dcsync: dump krbtgt → dc01 ✓ domain admin
- Learning
- Hack The Box — Active Directory track
- Research
- OAuth 2.0 & JWT implementation flaws
- Building
- OmniScanner v1.5 — PE support
- Next writeup
- PortSwigger practitioner labs: SSRF
01 // ENUMERATE
The numbers, and the toolbox
What I've shipped so far, and what I reach for when I sit down at a target.
- 3
- Writeups published
- 7
- Posts in total
- 24
- Topics covered
- 2023
- Hacking since
- Burp Suite
- nmap
- Ghidra
- BloodHound
- Impacket
- NetExec
- gobuster
- Wireshark
- pwndbg
- Wazuh
- Suricata
- Sysmon
- Python
- Go
- Rust
- Docker
- Ansible
- Linux
02 // EXPLOIT
Boxes I've broken
Walkthroughs of the machines, labs and CVEs I found most instructive: recon to root, with the reasoning kept in.

TryHackMe: Pickle Rick Walkthrough
A Rick and Morty themed CTF challenge requiring web reconnaissance, unauthenticated command injection exploitation, and sudo privilege escalation to retrieve all three secret ingredients.
Aug 5, 2026 · 1 min read
PortSwigger OAuth 2.0 Account Takeover
Exploiting unvalidated redirect URIs and implicit grant token leaks to achieve pre-auth account takeover.
Aug 1, 2026 · 1 min read

Active Directory Attack Chain: AS-REP Roasting to DCSync
Full attack path from unauthenticated AS-REP roasting to BloodHound ACL traversal and DCSync domain compromise.
Jul 20, 2026 · 1 min read
03 // ESCALATE
Things I've built
Tools and labs that grew out of getting stuck on something and wanting it to never happen again.
OmniScanner
Async Rust CLI that triages ELF binaries for risky patterns before I open them in Ghidra.
- Rust
- tokio
- goblin
- SARIF
Home SOC Lab
A small blue-team lab on a second-hand mini PC running Proxmox, used to practise detection engineering.
- Proxmox
- Wazuh
- Suricata
- Sysmon
ADLab-in-a-Box
Vagrant + Ansible scripts that spin up an intentionally vulnerable Active Directory domain in about 20 minutes.
- Vagrant
- Ansible
- PowerShell
- Windows Server
subsweep
Fast recon helper that chains passive subdomain sources, resolves them, and probes for live web services.
- Go
- goroutines
- crt.sh
- Chromium headless
04 // PERSIST
Latest from the lab
The newest posts across every collection, most recent first.
- [Writeup]TryHackMe: Pickle Rick Walkthrough→1 min read
- [Research]Case Study: OAuth 2.0 Redirect URI Bypass & Account Takeover→1 min read
- [Project]OmniScanner v1.5→1 min read
- [CheatSheet]Nmap Speed & Enumeration Cheatsheet→1 min read
- [Post]My 2026 Cybersecurity Learning Roadmap & CTF Preparation→1 min read
- [Writeup]PortSwigger OAuth 2.0 Account Takeover→1 min read