Offensive Security Certified Professional+
The flagship hands-on pentest cert — a 24-hour practical exam compromising real machines end-to-end, backed by a professional report.
verify credentialCybersecurity Graduate Student · CTF player · offensive security
>
A Linux box running a Flask-based wallpaper-sharing app — testing a filename path-traversal LFI to read application source, credential recovery from leaked backend code, a sudo-permitted Node.js scraper binary, and a real-world script-injection vulnerability in the happy-dom library for the path to root.
A Linux box exposing a leaked .git repository alongside a public-facing SOPlanning instance — testing git-history mining for plaintext database credentials, direct database manipulation to reset an application login, a real-world authenticated RCE, cron-exposed credential reuse, and a writable Flask app run with elevated sudo permissions for the path to root.
A Linux box running MantisBT bug tracker — testing exploitation of a rogue-MySQL-server arbitrary file-read CVE to steal application database credentials, offline hash cracking for admin access, an authenticated configuration-based RCE technique, and cron-job credential exposure combined with unrestricted sudo for the path to root.
A Linux box running Tiny File Manager instrumented with the PHP-SPX profiler — testing discovery of a low-profile CVE via a leaked phpinfo page, a path-traversal read of application source to recover and crack login hashes, and a sudo-permitted make install target for the path to root.
A Linux box running JetBrains TeamCity behind a marketing site — testing exploitation of a real-world authentication-bypass CVE to enable debug-mode command execution, mining git commit history for a removed SSH key, offline key/password cracking, a chain of leaked credentials across several users, and a GTFOBins sudo escape for the path to root.
A Linux box running a file-zipping web app — testing a PHP filter-wrapper LFI to read source code, a `zip://` PHP-wrapper technique to execute an uploaded archive as code for a foothold, and a root-owned backup cron job whose password-protected archive leaks the root password for the path to root.
AI tutoring wrapper that learns from a SKILL.md and your lecture transcripts to tutor in your professor's style, citing the source material.
PowerShell tool that auto-rotates local Windows account passwords on a schedule for NIST 800-63B compliance.
Capture-the-flag challenges I've authored — sources, configs, and solution notes.
The flagship hands-on pentest cert — a 24-hour practical exam compromising real machines end-to-end, backed by a professional report.
verify credentialHands-on entry pentest cert — host/network enumeration, exploitation, and pivoting in a live lab exam.
verify credential
Foundational security cert covering threats, cryptography, IAM, and risk — the industry baseline.
verify credential
Cloud fundamentals — core AWS services, the shared-responsibility model, billing, and security basics.
verify credentialSecurity enthusiast who goes by the handle fletcher.
Graduate cybersecurity student who spends entirely too much time on Hack The Box. I write up the machines I root, build tooling when a workflow gets repetitive, and chase the next certification. Mostly offensive security, with forensics and incident response close behind.