Skip to content

xomnibot · Security Researcher & Systems Enthusiast

Cybersecurity Whiz & Open Source Builder

To make technical cybersecurity research fun, accessible, and 100% practical through code, CTF teardowns, and open-source software.

lab-01 / attack-path
kaliattackerweb01:80mail01:25app01:8080ws01:3389db01:1433fs01:445dc01DC
  1. [1] recon: nmap -sV web01 → 80/tcp open
  2. [2] exploit: command injection → shell as www-data
  3. [3] pivot: creds in config → app01
  4. [4] kerberoast: svc_sql hash cracked → db01
  5. [5] dcsync: dump krbtgt → dc01 ✓ domain admin
Learning
Hack The Box — Active Directory track
Research
OAuth 2.0 & JWT implementation flaws
Building
OmniScanner v1.5 — PE support
Next writeup
PortSwigger practitioner labs: SSRF

01 // ENUMERATE

The numbers, and the toolbox

What I've shipped so far, and what I reach for when I sit down at a target.

3
Writeups published
7
Posts in total
24
Topics covered
2023
Hacking since
  • Burp Suite
  • nmap
  • Ghidra
  • BloodHound
  • Impacket
  • NetExec
  • gobuster
  • Wireshark
  • pwndbg
  • Wazuh
  • Suricata
  • Sysmon
  • Python
  • Go
  • Rust
  • Docker
  • Ansible
  • Linux

05 // EXFIL

Exfiltrate a message

Questions about a writeup, a CTF team invite, an internship — my inbox is open.

Email me