Search

c0rvex

Penetration tester. Occasionally breaks things for a living.

This site is a personal notebook — HTB machine walkthroughs posted after retirement, anonymised findings from real-world engagements, and short technical notes from the day-to-day.

Everything published here is either CTF/lab-based or covers publicly-known vulnerabilities. Real-world content is fully anonymised: no client names, no internal hostnames, no identifiable infrastructure. See the disclaimer for the full responsible-disclosure policy.

  • OSCP Offensive Security
  • CEH EC-Council
  • CompTIA Security+ CompTIA

Active on HackTheBox — Hacker rank. Writeups for retired machines are published here once the official walkthrough is released.

HTB Profile
  • Web application penetration testing
  • Network and infrastructure assessments
  • Active Directory and Windows environment attacks
  • Red team operations and adversary simulation
  • Vulnerability research and CVE analysis

Available for freelance engagements and consulting. Currently focused on Active Directory attack paths and cloud security research. See /now for what I'm working on this month.

For encrypted communication, my public key is available on keys.openpgp.org.