Skip to content

whoami

xomnibot

Security Researcher & Systems Enthusiast

I'm a 21-year-old computer science student who got hooked on security the first time I popped a shell on an OverTheWire level.

xomnibot labclearance: learning

xomnibot

Security Researcher & Systems Enthusiast

Focus
Hack The Box — Active Directory track
Building
OmniScanner v1.5 — PE support
Stack
Python · Go · Rust · Bash
Since
2023

ID 6DF14B1Exomnibot.in

cat bio.txt

The story so far

I'm a 21-year-old computer science student who got hooked on security the first time I popped a shell on an OverTheWire level. Since then I've spent most of my evenings in CTFs, homelabs and Burp Suite, trying to understand how things break — and how to stop them breaking.

I like the full loop: find the bug, understand the root cause, write the exploit, then build the detection or the fix. Everything I learn ends up here as a writeup, a cheatsheet or a small open-source tool, so the next person can learn it faster than I did.

ls -la ~/projects

Things I've built

Tools and labs that came out of the CTF and homelab hours.

drwxr-xr-x xomnibot 6 projects

  • Async Rust CLI that triages ELF binaries for risky patterns before I open them in Ghidra.

    • Flags missing hardening (NX, PIE, RELRO, canaries) and dangerous libc imports
    • Scores functions by reachability of unsafe calls to prioritise manual review
    • JSON + SARIF output so results drop straight into CI
    • Rust
    • tokio
    • goblin
    • SARIF
  • Home SOC Lab

    Active

    A small blue-team lab on a second-hand mini PC running Proxmox, used to practise detection engineering.

    • Wazuh SIEM + Suricata IDS + Sysmon on Windows endpoints
    • 25+ custom detection rules mapped to MITRE ATT&CK, tested with Atomic Red Team
    • Attack → alert → write-up workflow for every technique I learn
    • Proxmox
    • Wazuh
    • Suricata
    • Sysmon
    • Sigma
  • ADLab-in-a-Box

    Stable

    Vagrant + Ansible scripts that spin up an intentionally vulnerable Active Directory domain in about 20 minutes.

    • Two-DC forest with seeded misconfigurations: Kerberoastable SPNs, AS-REP roastable users, weak ACLs
    • Reset-to-snapshot so each practice run starts clean
    • Companion attack-path notes using BloodHound, Impacket and NetExec
    • Vagrant
    • Ansible
    • PowerShell
    • Windows Server
  • subsweep

    Stable

    Fast recon helper that chains passive subdomain sources, resolves them, and probes for live web services.

    • Pulls from certificate transparency logs and public DNS datasets
    • Concurrent resolution with wildcard-DNS filtering
    • Screenshots + tech fingerprinting for quick triage of large scopes
    • Go
    • goroutines
    • crt.sh
    • Chromium headless
  • JWT Inspector (Burp extension)

    Active

    Burp Suite extension that highlights JWTs in traffic and tests common implementation flaws in one click.

    • Checks alg=none, HS/RS key confusion, weak HMAC secrets and missing expiry
    • Built on the Montoya API with a small custom UI tab
    • Born out of the OAuth / JWT research on this site
    • Java
    • Burp Montoya API
    • JWT
  • Cowrie Honeypot Study

    Archived

    Ran an SSH honeypot on a $5 VPS for 30 days and analysed what real attackers try first.

    • Logged thousands of login attempts and dozens of dropped payloads
    • Clustered credential lists and bot behaviour with pandas
    • Dashboards in Grafana; findings written up on the blog
    • Cowrie
    • Python
    • pandas
    • Grafana

./skills --matrix

What I can actually do

Every technique below is backed by a lab, a writeup or a project.

scroll the matrix

TA01 · 3 techniques

Web application testing

  • T01.01Find and exploit IDOR, SSRF, SQLi, XSS, and auth/session flaws end to end
  • T01.02Audit OAuth 2.0 and JWT flows for redirect, state and key-confusion bugs
  • T01.03Write clear reports with impact, reproduction steps and fixes

TA02 · 3 techniques

Active Directory

  • T02.01Enumerate domains with BloodHound and map attack paths
  • T02.02Kerberoasting, AS-REP roasting, ACL abuse, DCSync
  • T02.03Explain the detection for each technique, not just the exploit

TA03 · 3 techniques

Linux & privilege escalation

  • T03.01Enumerate and abuse sudo, SUID, capabilities, cron and PATH issues
  • T03.02Comfortable living in the terminal: Bash, systemd, networking, logs
  • T03.03Harden what I break: least privilege, auditd, fail2ban

TA04 · 3 techniques

Reverse engineering & binaries

  • T04.01Read x86-64 disassembly in Ghidra and debug with GDB + pwndbg
  • T04.02Stack-based buffer overflows, ret2libc and basic ROP chains
  • T04.03Static triage of unknown binaries (see OmniScanner)

TA05 · 3 techniques

Detection & blue team

  • T05.01Write Sigma and Wazuh rules from attack telemetry
  • T05.02Hunt through Sysmon, Windows Event and web server logs
  • T05.03Map findings to MITRE ATT&CK

TA06 · 3 techniques

Tooling & automation

  • T06.01Build CLI tools in Python, Go and Rust
  • T06.02Automate labs with Docker, Vagrant and Ansible
  • T06.03Ship with Git, CI and readable docs
Offensive
Web SecurityActive DirectoryBinary ExploitationReverse EngineeringAPI Security
Defensive
Threat HuntingMalware AnalysisPatch DiffingLog Auditing
Development
PythonC / C++TypeScriptRustDockerLinux
AI Security
Prompt InjectionAgentic AI AuditLLM Sandbox Security

learning --log

Quest log

Where I am on the path, and what unlocks next.

  1. TryHackMe — Jr Penetration Tester path

    Web, network and privesc fundamentals

    Completed

  2. PortSwigger Web Security Academy

    Working through the practitioner labs topic by topic

    In progress

  3. Hack The Box — Active Directory machines

    Retired AD boxes, written up as I go

    In progress

  4. OSCP preparation

    Structured prep once the AD track is done

    Next up

git log --graph --oneline

Commit history

Milestones, newest first.

  1. e63e2b6tag: 2026Platform

    Launched xomnibot.in

    Moved all my notes, writeups and tools into one place, with a publishing flow that turns plain Markdown into posts.

  2. 053347ctag: 2026Tool

    OmniScanner v1.0 released

    First public release of my Rust binary-triage CLI, now used in my own reverse-engineering workflow.

  3. 343159atag: 2025Research

    OAuth & JWT research series

    Deep dives into OAuth 2.0 state and redirect flaws, plus a Burp extension for testing JWT implementations.

  4. 286bd33tag: 2025Milestone

    Built an Active Directory attack lab

    Automated a vulnerable two-DC domain with Vagrant + Ansible and worked through Kerberoasting, ACL abuse and DCSync.

  5. 9e6e09ftag: 2024Milestone

    Home SOC lab + honeypot study

    Set up Wazuh, Suricata and Sysmon at home and ran a 30-day SSH honeypot to see real attacker behaviour.

  6. ad8da10tag: 2024CTF

    First university CTF team

    Co-founded a small CTF team with classmates; weekly practice on web and pwn challenges.

  7. 9f2483atag: 2023Milestone

    Started with Linux and OverTheWire

    Daily-drove Linux, finished Bandit, and started the TryHackMe learning paths. That was it — hooked.

cat ~/.config/rig

The setup

What I run everything on, written down as a dotfile.

~/.config/rig.toml

          
          # ~/.config/rig.toml, xomnibot@lab
        
          
          [machine]
        
          
          os = "Arch Linux (Hyprland) + Kali VM"
        
          
          terminal = "Kitty + Zsh + Neovim"
        
          
          editor = "VS Code + Neovim"
        
          
          hardware = "ThinkPad T14 (32GB) + second-hand mini PC running Proxmox"
        
          
           
        
          
          [toolbox]
        
          
          languages = ["Python", "Go", "Rust", "Bash"]
        
          
          tools = ["Burp Suite", "Ghidra", "BloodHound", "Impacket", "NetExec"]
        

./contact

Let's talk security.

Have a bug, a box, a collaboration idea or just a question? My inbox is open.