Open to Work · Available for Engagements

Hi, I'm ANXS3C

Red Team Operator
🕵︎
📜

I will post my CV soon

In the meantime, feel free to contact me directly for more information.

0 Machines Rooted Proving Grounds
0 Web Labs Proving Grounds
0 CVEs Exploited Research · POCs
0 Writeups Technical Research
0 Clients Freelance · Consulting

Offensive Security

I specialize in Active Directory and web application penetration testing

My approach combines manual methodology with custom automation to simulate sophisticated attack chains

With a commitment to continuous learning, I maintain an aggressive lab schedule to stay ahead of emerging threats and TTPs

Red Team Active Directory Linux Exploitation Web Pentesting Network Pivoting

Core Capabilities

Specialized skills across the full offensive security spectrum

Linux Security

Assessing, exploiting, and securing Linux environments through deep understanding of operating system internals and security controls

Linux PrivEscKernel ExploitationGTFOBinsCapabilities AbuseContainer EscapeLinPEASsystemdSUID/SGID

Active Directory Security

Evaluating enterprise identity infrastructures to identify attack paths, privilege escalation opportunities, and domain-level security weaknesses

BloodHoundSharpHoundPowerViewRubeusMimikatzKerberoastingDCSyncRBCDGolden TicketPass-the-Hash

Web Security

Identifying and validating vulnerabilities in modern web applications and APIs through comprehensive security testing methodologies

Burp SuiteSQL InjectionXSSSSRFSSTIGraphQL SecurityAPI SecurityNucleiFFUFSQLMap

ICS / OT Security

Assessing industrial environments and critical systems to identify risks affecting operational resilience and security

SCADAPLC SecurityModbusDNP3Industrial ProtocolsWiresharkProcess ControlOT Assessment

Network Security

Analyzing network infrastructures to discover weaknesses, exposed services, and opportunities for unauthorized access

NmapRustscanMasscanWiresharktcpdumpARP PoisoningDNS SpoofingMITMPacket AnalysisNetcat

Privilege Escalation

Identifying and exploiting security weaknesses that enable elevated access on compromised systems

Linux PrivEscWindows PrivEscKernel ExploitsSUID/SGIDSudo AbusePath HijackingDocker EscapeService Misconfigurations

EDR Evasion

Understanding defensive technologies and evaluating their effectiveness against advanced offensive techniques

Indirect SyscallsAMSI BypassETW PatchingProcess InjectionStack SpoofingAPI UnhookingShellcode LoadersMemory Evasion

Lateral Movement

Simulating adversary movement across enterprise environments to assess internal security boundaries and access controls

PsExecWMIWinRMSMBExecPSRemotingSSH TunnelingProxychainsRemote Operations

Persistence Techniques

Evaluating the effectiveness of security controls against long-term access and post-compromise activities

Scheduled TasksRegistry Run KeysWMI PersistenceStartup ItemsSSH KeysSystemd ServicesService Persistence

Data Exfiltration

Assessing how sensitive information can be accessed, transferred, and protected within enterprise environments

DNS TunnelingICMP TunnelingSCPFTPHTTPS ExfiltrationCovert ChannelsEncrypted Transfer

Network Pivoting

Navigating segmented infrastructures to evaluate trust relationships and internal attack surface exposure

Ligolo-ngChiselSOCKS ProxyPort ForwardingSSH PivotingProxychainsInternal RoutingC2 Infrastructure

Programming & Automation

Developing custom tools and automation solutions to support security research and assessments

PythonBashCPowerShellCustom ToolingAutomation

Featured Work

Projects and Penetration Testing Labs

Security Projects

Active

Shellcode Loader · EDR Evasion

Windows shellcode loader with XOR encryption and EDR evasion. Python encrypter and C++ loader

C++PythonEDR Evasion
C++/Python
GitHub →
Active

Linux Persistence Toolkit

Bash-based framework for analyzing, simulating, and detecting Linux persistence mechanisms

BashLinuxPurple Team
Shell Red & Blue
GitHub →
In Progress

ADEnum Suite

Automated Active Directory enumeration and attack framework with BloodHound integration

PythonActive DirectoryBloodHound
Python Red Team
GitHub →
In Progress

PivotLab

Docker-based network pivoting lab for lateral movement, tunneling, and C2 infrastructure practice.

DockerChiselPivoting
Docker Pivoting
GitHub →

Web Security Labs

Active

Access Control

IDOR, privilege escalation, insecure direct object references

IDORPrivilege Escalation
Access Control Labs →
Active

File Upload

Web shells, RCE, file upload bypass techniques

Web ShellRCE
File Upload Labs →
Active

Authentication

Session management, brute force, MFA bypass

Session ManagementMFA Bypass
Authentication Labs →
Active

Cross‑Site Scripting (XSS)

Reflected, stored, and DOM‑based XSS attacks

Reflected XSSDOM XSS
XSS Labs →
Active

SQL Injection

Union‑based, blind, error‑based SQL injection

Union‑basedBlind SQLi
SQLi Labs →
Active

CSRF

Request forgery, state‑changing attacks

CSRFRequest Forgery
CSRF Labs →
Active

Clickjacking

UI redressing, iframe exploitation

UI RedressingIframe
Clickjacking Labs →
Active

DOM‑Based

DOM XSS, client‑side injection

DOM XSSClient‑side
DOM Labs →
Active

CORS

CORS misconfiguration, data exfiltration

CORSOrigin Spoofing
CORS Labs →
Active

XXE Injection

File disclosure, SSRF via XXE

XXESSRF
XXE Labs →
Active

SSRF

Cloud metadata, internal service access

SSRFCloud Metadata
SSRF Labs →
Active

Request Smuggling

Desync attacks, CL‑TE, TE‑CL

DesyncCL‑TE
Request Smuggling →
Active

OS Command Injection

RCE, command injection, shell access

RCECommand Injection
OS Command Labs →
Active

SSTI

Template engine exploitation, RCE

SSTIRCE
SSTI Labs →
Active

Path Traversal

Directory traversal, file disclosure

Directory TraversalFile Disclosure
Path Traversal Labs →
Active

WebSockets

Message manipulation, WS security

WebSocketsMessage Manipulation
WebSockets Labs →
Active

Cache Poisoning

Cache poisoning, cache deception

Cache PoisoningCache Deception
Cache Poisoning Labs →
Active

Insecure Deserialization

Object injection, RCE via deserialization

DeserializationObject Injection
Deserialization Labs →
Active

Info Disclosure

Info leaks, error messages, debug mode

Info LeakDebug Mode
Info Disclosure Labs →
Active

Business Logic

Logic flaws, workflow bypass, transaction abuse

Logic FlawsTransaction Abuse
Business Logic Labs →
Active

Host Header Attacks

Password reset poisoning, cache poisoning

Host HeaderPassword Reset
Host Header Labs →
Active

OAuth

Token abuse, authorization flaws

OAuthToken Abuse
OAuth Labs →
Active

JWT

Algorithm confusion, signature bypass

JWTAlgorithm Confusion
JWT Labs →
Active

Essential Skills

Enumeration, fuzzing, reconnaissance

EnumerationFuzzing
Essential Skills Labs →
Active

Prototype Pollution

RCE, object manipulation, bypass controls

Prototype PollutionRCE
Prototype Pollution Labs →
Active

GraphQL

Introspection, injection, DoS

GraphQLIntrospection
GraphQL Labs →
Active

Race Conditions

TOCTOU, privilege escalation, data corruption

Race ConditionTOCTOU
Race Conditions Labs →
Active

NoSQL Injection

MongoDB, injection, data extraction

NoSQLMongoDB
NoSQL Labs →
Active

API Testing

REST API, authentication, authorization

REST APIAPI Security
API Testing Labs →
Active

Web LLM Attacks

Prompt injection, data leakage

LLMPrompt Injection
Web LLM Labs →
Active

Cache Deception

Data exposure, cache exploitation

Cache DeceptionData Exposure
Cache Deception Labs →

42 School – C Projects

Completed

Born2beroot

Linux system administration and virtualization

LinuxVirtualization
GitHub →
Completed

Minishell

Bash‑inspired shell with pipes, signals, built‑ins

CUnix
GitHub →
Completed

Philosophers

Dining Philosophers with threads and mutexes

ThreadsMutex
GitHub →
Completed

Minitalk

Client/Server communication using signals

SignalsIPC
GitHub →
Completed

Push_swap

Sorting algorithm with stack operations

AlgorithmsStack
GitHub →
Completed

Get_next_line

Line‑by‑line file reader with buffer management

File I/OBuffer
GitHub →
Completed

Ft_printf

Custom printf implementation

FormattingVariadic Functions
GitHub →
Completed

Libft

Reimplementation of C standard library

LibraryFundamentals
GitHub →
Completed

Fractol

Interactive fractal renderer

GraphicsMath
GitHub →

Compromised Machines

01

Support

WindowsRooted
ADRBCD · DCSync · LDAP
SMB AccessBinary AnalysisXOR DecryptionLDAP EnumerationRBCDDCSync
Read →
02

Eighteen

WindowsRooted
ADMSSQL · BadSuccessor
MSSQL ImpersonationPassword SprayingBadSuccessor AttackdMSA Creation
Read →
03

Abducted

LinuxRooted
PrivEscSamba · systemd
Samba CVE‑2026‑4480Print Job InjectionSSH Key Injectionsystemd Drop‑in
Read →
04

Snapped

LinuxRooted
LPESnapd · Race
Snapd LPE CVE‑2026‑3888Race Conditionsystemd‑tmpfilesSUID Bash Persistence
Read →
05

TwoMillion

LinuxRooted
Web → KernelOverlayFS
JS DeobfuscationAPI EnumerationOS Command InjectionOverlayFS Kernel Exploit
Read →
06

Editor

LinuxRooted
Web → RootXWiki · PATH
XWiki RCE CVE‑2025‑24893SSH AccessPATH HijackingCVE‑2024‑32019
Read →
07

Facts

LinuxRooted
CMS → RootCamaleon · Facter
Camaleon CMS v2.9.0CVE‑2025‑2304CVE‑2024‑46987Facter Custom RCE
Read →
08

Devvortex

LinuxRooted
CMS → RootJoomla · apport
Virtual Host DiscoveryJoomla CVE‑2023‑23752MySQL Accessapport‑cli LPE
Read →
09

Lame

LinuxRooted
SMBSamba · usermap
SMB EnumerationSamba CVE‑2007‑2447Metasploitusermap_script
Read →
10

Cap

LinuxRooted
IDOR → RootPCAP · setuid
IDORPCAP Traffic AnalysisCredential ReusePython setuid Exploit
Read →
11

CCTV

LinuxRooted
SQLi → RootZoneMinder · motionEye
ZoneMinder Default CredsBlind SQLi CVE‑2024‑51482Bcrypt Hash CrackingmotionEye RCE
Read →
12

Reactor

LinuxRooted
Node.js → RootNext.js · Debugger
Next.js RCE CVE‑2025‑55182SQLite DB ExtractionMD5 Hash CrackingNode.js Inspector Debugger
Read →
13

WingData

LinuxRooted
FTP → RootWing · Baron Samedit
Wing FTP ServerAnonymous FTP AccessDirectory TraversalBaron Samedit CVE‑2021‑3156
Read →
14

Expressway

LinuxRooted
VPNIPsec · Chroot
IKE/IPsec DiscoveryPSK CrackingSudo Chroot BypassCVE‑2025‑32463
Read →
15

SeaPanda

ICS/OTReconstructed
IndustrialModbus · PLC
USB InfectionProcess HollowingSplunkModbus ManipulationPLC Logic Deployment
Read →
16

Academy

LinuxIn Progress
Web → RootLaravel
Laravel Debug ModeRCESQL InjectionPrivilege Escalation
17

Admirer

LinuxIn Progress
Web → RootAdminer
AdminerMySQL File ReadPython Library HijackingSUID Exploit
18

OpenAdmin

LinuxIn Progress
Web → RootOpenNetAdmin
OpenNetAdmin RCESSH Key ExtractionSudo NANOPrivilege Escalation
19

Forest

WindowsIn Progress
ADAS‑REP · DCSync
AS‑REP RoastingBloodHoundKerberoastingDCSync
20

Active

WindowsIn Progress
ADGPP · Kerberoast
SMB EnumerationGroup PolicyKerberoastingGPP Password
21

Sauna

WindowsIn Progress
ADAS‑REP · DCSync
AS‑REP RoastingBloodHoundKerberoastingDCSync
22

Monteverde

WindowsIn Progress
ADAzure AD · RDP
SMB EnumerationAzure AD ConnectPassword SprayingRDP Access
23

Legacy

WindowsIn Progress
SMBMS08‑067
SMB EnumerationMS08‑067MetasploitSystem Access
24

Blue

WindowsIn Progress
EternalBlueMS17‑010
SMB EnumerationMS17‑010EternalBlueDoublePulsar
25

Devel

WindowsIn Progress
FTP → WebASP.NET · IIS
Anonymous FTPASP.NET RCEIIS CompromiseSYSTEM Access
26

Netmon

WindowsIn Progress
PRTG → RootRCE
PRTG Network MonitorDefault CredentialsRCESYSTEM Access
27

Nest

WindowsIn Progress
ADKerberoast · DCSync
SMB EnumerationKerberoastingPass‑the‑HashDCSync
Showing 16 of 27 machines

Technical Writeups

Detailed walkthroughs and vulnerability research

June 2026ADMedium

Support — AD Enumeration to Domain Admin

Complete walkthrough covering RBCD abuse and DCSync attacks.

BloodHoundRBCD
Read →
May 2026LinuxEasy

Editor — XWiki RCE to PATH Hijacking

Exploiting XWiki and leveraging PATH hijacking for privilege escalation.

XWikiPATH
Read →
April 2026ICSHard

SeaPanda — ICS/OT Network Compromise

Modbus analysis and PLC exploitation in industrial environment.

ModbusPLC
Read →
March 2026WebMedium

TwoMillion — Web Enumeration to Kernel Exploit

From web app enumeration to OverlayFS kernel exploitation.

KernelOverlayFS
Read →

Certifications

Foundational

Red Teaming

TryHackMe

Earned · Mar 2026

Web Application Pentesting

TryHackMe

Earned · Mar 2026

SC‑100: Design Security Operations

Microsoft

Earned · Nov 2025

Python 3

CodinGame

Earned · Nov 2025

Cybersecurity Analyst

IBM · Coursera

Earned · Nov 2025

Professional

CRTP

Certified Red Team Professional

In Progress

eWPTX

Web Penetration Tester eXtreme

In Progress

CRTO

Certified Red Team Operator

Planned

OSCP

Offensive Security Certified Professional

Planned

Let's Work Together

Interested in security assessments or collaboration?

Available for freelance engagements
0 / 2000 characters
Your information is secure