Domain

Offensive Security

Attacking systems I own so the detections I write aren't guesswork.

I'm not trying to become a pentester. I want to know what an attack looks like from the other side, because that's the difference between a detection rule that works and one that sounds right.

Everything here runs against machines I own or targets built to be broken.

Coursework: graduate Penetration Testing and Ethical Hacking at Eller, including a full penetration test report, plus red team and blue team group engagements.
Roadmap

What's next

Listed before it exists so you can tell the difference.

Cloud attack paths

Privilege escalation and lateral movement against a deliberately misconfigured copy of my own Azure builds.

Offensive Security Planned
Purple team loop

Run the attack, write the detection, tune it, document both halves.

Offensive Security Planned
Manual exploitation

Replacing Metasploit modules with my own Python and Bash to cut down the forensic artifacts a framework leaves behind.

Offensive Security Planned