Privilege escalation and lateral movement against a deliberately misconfigured copy of my own Azure builds.
Domain
Offensive Security
Attacking systems I own so the detections I write aren't guesswork.
I'm not trying to become a pentester. I want to know what an attack looks like from the other side, because that's the difference between a detection rule that works and one that sounds right.
Everything here runs against machines I own or targets built to be broken.
Coursework: graduate Penetration Testing and Ethical Hacking at Eller, including a full penetration test report, plus red team and blue team group engagements.
Roadmap
What's next
Listed before it exists so you can tell the difference.
Cloud attack paths
Offensive Security
Planned
Purple team loop
Run the attack, write the detection, tune it, document both halves.
Offensive Security
Planned
Manual exploitation
Replacing Metasploit modules with my own Python and Bash to cut down the forensic artifacts a framework leaves behind.
Offensive Security
Planned