HTB: Logging
Leaked SMB credential with predictable year rotation → gMSA hash extraction → WinRM → DLL hijack → AD CS rogue cert → DNS poisoning → fake WSUS server → SYSTEM.
What I did: Architected and deployed scalable enterprise IT infrastructures.
What I do now: Secure critical networks, lead and develop Mindflow.care as founder.
What I love to do: Security research, custom tools, CTFs, lab from HTB/THM and anime.
// Projects
Latest CVEs with their Proof of Concept exploits.
Enterprise-style Ubuntu 22.04 hardening with audit, remediation, rollback, and compliance reporting.
Autonomous AI pentesting engine performing continuous offensive security across web, cloud, AD and Kubernetes. Uses agentic reasoning, real exploit execution and attack path analysis to deliver proof-based vulnerabilities.
// Writing
Leaked SMB credential with predictable year rotation → gMSA hash extraction → WinRM → DLL hijack → AD CS rogue cert → DNS poisoning → fake WSUS server → SYSTEM.
Kobold is a medium Linux box that chains a misconfigured MCP developer tool into full root. An unauthenticated RCE in the MCPJam Inspector API (CVE-2026-23744) drops a shell as ben via unsanitized command injection through child_process.spawn(). Privilege escalation abuses a dormant Docker group membership activatable via newgrp docker, from there it's a one-liner container escape mounting the host filesystem for root.
// Credentials
// Contact
Open to collaborations and security research.
// contact.channels[]
WifiForge is a tool developed by Black Hills InfoSec to help train Pentesters on different Wi-Fi attack vectors and Wireless capabilities.