whoami
xomnibot
Security Researcher & Systems Enthusiast
I'm a 21-year-old computer science student who got hooked on security the first time I popped a shell on an OverTheWire level.
xomnibot
Security Researcher & Systems Enthusiast
- Focus
- Hack The Box — Active Directory track
- Building
- OmniScanner v1.5 — PE support
- Stack
- Python · Go · Rust · Bash
- Since
- 2023
ID 6DF14B1Exomnibot.in
cat bio.txt
The story so far
I'm a 21-year-old computer science student who got hooked on security the first time I popped a shell on an OverTheWire level. Since then I've spent most of my evenings in CTFs, homelabs and Burp Suite, trying to understand how things break — and how to stop them breaking.
I like the full loop: find the bug, understand the root cause, write the exploit, then build the detection or the fix. Everything I learn ends up here as a writeup, a cheatsheet or a small open-source tool, so the next person can learn it faster than I did.
ls -la ~/projects
Things I've built
Tools and labs that came out of the CTF and homelab hours.
drwxr-xr-x xomnibot 6 projects
OmniScanner
ActiveAsync Rust CLI that triages ELF binaries for risky patterns before I open them in Ghidra.
- Flags missing hardening (NX, PIE, RELRO, canaries) and dangerous libc imports
- Scores functions by reachability of unsafe calls to prioritise manual review
- JSON + SARIF output so results drop straight into CI
- Rust
- tokio
- goblin
- SARIF
Home SOC Lab
ActiveA small blue-team lab on a second-hand mini PC running Proxmox, used to practise detection engineering.
- Wazuh SIEM + Suricata IDS + Sysmon on Windows endpoints
- 25+ custom detection rules mapped to MITRE ATT&CK, tested with Atomic Red Team
- Attack → alert → write-up workflow for every technique I learn
- Proxmox
- Wazuh
- Suricata
- Sysmon
- Sigma
ADLab-in-a-Box
StableVagrant + Ansible scripts that spin up an intentionally vulnerable Active Directory domain in about 20 minutes.
- Two-DC forest with seeded misconfigurations: Kerberoastable SPNs, AS-REP roastable users, weak ACLs
- Reset-to-snapshot so each practice run starts clean
- Companion attack-path notes using BloodHound, Impacket and NetExec
- Vagrant
- Ansible
- PowerShell
- Windows Server
subsweep
StableFast recon helper that chains passive subdomain sources, resolves them, and probes for live web services.
- Pulls from certificate transparency logs and public DNS datasets
- Concurrent resolution with wildcard-DNS filtering
- Screenshots + tech fingerprinting for quick triage of large scopes
- Go
- goroutines
- crt.sh
- Chromium headless
JWT Inspector (Burp extension)
ActiveBurp Suite extension that highlights JWTs in traffic and tests common implementation flaws in one click.
- Checks alg=none, HS/RS key confusion, weak HMAC secrets and missing expiry
- Built on the Montoya API with a small custom UI tab
- Born out of the OAuth / JWT research on this site
- Java
- Burp Montoya API
- JWT
Cowrie Honeypot Study
ArchivedRan an SSH honeypot on a $5 VPS for 30 days and analysed what real attackers try first.
- Logged thousands of login attempts and dozens of dropped payloads
- Clustered credential lists and bot behaviour with pandas
- Dashboards in Grafana; findings written up on the blog
- Cowrie
- Python
- pandas
- Grafana
./skills --matrix
What I can actually do
Every technique below is backed by a lab, a writeup or a project.
scroll the matrix
TA01 · 3 techniques
Web application testing
- T01.01Find and exploit IDOR, SSRF, SQLi, XSS, and auth/session flaws end to end
- T01.02Audit OAuth 2.0 and JWT flows for redirect, state and key-confusion bugs
- T01.03Write clear reports with impact, reproduction steps and fixes
TA02 · 3 techniques
Active Directory
- T02.01Enumerate domains with BloodHound and map attack paths
- T02.02Kerberoasting, AS-REP roasting, ACL abuse, DCSync
- T02.03Explain the detection for each technique, not just the exploit
TA03 · 3 techniques
Linux & privilege escalation
- T03.01Enumerate and abuse sudo, SUID, capabilities, cron and PATH issues
- T03.02Comfortable living in the terminal: Bash, systemd, networking, logs
- T03.03Harden what I break: least privilege, auditd, fail2ban
TA04 · 3 techniques
Reverse engineering & binaries
- T04.01Read x86-64 disassembly in Ghidra and debug with GDB + pwndbg
- T04.02Stack-based buffer overflows, ret2libc and basic ROP chains
- T04.03Static triage of unknown binaries (see OmniScanner)
TA05 · 3 techniques
Detection & blue team
- T05.01Write Sigma and Wazuh rules from attack telemetry
- T05.02Hunt through Sysmon, Windows Event and web server logs
- T05.03Map findings to MITRE ATT&CK
TA06 · 3 techniques
Tooling & automation
- T06.01Build CLI tools in Python, Go and Rust
- T06.02Automate labs with Docker, Vagrant and Ansible
- T06.03Ship with Git, CI and readable docs
- Offensive
- Web SecurityActive DirectoryBinary ExploitationReverse EngineeringAPI Security
- Defensive
- Threat HuntingMalware AnalysisPatch DiffingLog Auditing
- Development
- PythonC / C++TypeScriptRustDockerLinux
- AI Security
- Prompt InjectionAgentic AI AuditLLM Sandbox Security
learning --log
Quest log
Where I am on the path, and what unlocks next.
TryHackMe — Jr Penetration Tester path
Web, network and privesc fundamentals
Completed
PortSwigger Web Security Academy
Working through the practitioner labs topic by topic
In progress
Hack The Box — Active Directory machines
Retired AD boxes, written up as I go
In progress
OSCP preparation
Structured prep once the AD track is done
Next up
git log --graph --oneline
Commit history
Milestones, newest first.
e63e2b6tag: 2026Platform
Launched xomnibot.in
Moved all my notes, writeups and tools into one place, with a publishing flow that turns plain Markdown into posts.
053347ctag: 2026Tool
OmniScanner v1.0 released
First public release of my Rust binary-triage CLI, now used in my own reverse-engineering workflow.
343159atag: 2025Research
OAuth & JWT research series
Deep dives into OAuth 2.0 state and redirect flaws, plus a Burp extension for testing JWT implementations.
286bd33tag: 2025Milestone
Built an Active Directory attack lab
Automated a vulnerable two-DC domain with Vagrant + Ansible and worked through Kerberoasting, ACL abuse and DCSync.
9e6e09ftag: 2024Milestone
Home SOC lab + honeypot study
Set up Wazuh, Suricata and Sysmon at home and ran a 30-day SSH honeypot to see real attacker behaviour.
ad8da10tag: 2024CTF
First university CTF team
Co-founded a small CTF team with classmates; weekly practice on web and pwn challenges.
9f2483atag: 2023Milestone
Started with Linux and OverTheWire
Daily-drove Linux, finished Bandit, and started the TryHackMe learning paths. That was it — hooked.
cat ~/.config/rig
The setup
What I run everything on, written down as a dotfile.
# ~/.config/rig.toml, xomnibot@lab
[machine]
os = "Arch Linux (Hyprland) + Kali VM"
terminal = "Kitty + Zsh + Neovim"
editor = "VS Code + Neovim"
hardware = "ThinkPad T14 (32GB) + second-hand mini PC running Proxmox"
[toolbox]
languages = ["Python", "Go", "Rust", "Bash"]
tools = ["Burp Suite", "Ghidra", "BloodHound", "Impacket", "NetExec"]
./contact
Let's talk security.
Have a bug, a box, a collaboration idea or just a question? My inbox is open.