[ SECTION_01 ]
Intro
Ethical Hacking graduate looking for a first role in offensive security or a SOC — the profile in brief.
whoami --full
role :: junior penetration tester / red team / SOC analyst focus :: active directory · web application · offensive tooling degree :: BSc (Hons) Ethical Hacking — 2:1, NCSC certified htb :: Master · level 65 — Zephyr, Dante Pro Labs, 80 CPE next :: HTB CPTS loc :: [REDACTED], Scotland # status: available for junior pentest / red team / SOC roles
I'm an Ethical Hacking graduate from Abertay University — a degree certified by the National Cyber Security Centre — looking for a first role in offensive security or a SOC.
I hold Hack The Box Master rank at level 65, with the Zephyr and Dante Pro Labs completed — 80 CPE credits combined. Zephyr is where most of my Active Directory experience comes from: relay attacks, pivoting, password attacks, privilege escalation and crossing trust boundaries across a multi-domain estate. I play HTB Seasons to keep my enumeration sharp between labs, and CPTS is my next certification.
I also build my own tooling. My Honours Project asked whether NixOS could replace Kali Linux as a reproducible, declarative offensive platform; IceBreaker is the environment that came out of it. Percival is a Rust OSINT tool covering 5,700+ sites, and DAEMONBins merges GTFOBins, LOLBAS and WADComs into one catalogue. Everything I learn gets written up publicly at daemon-sec.xyz.
I care as much about the report as the shell — clear, reproducible write-ups a client can act on.
[ SECTION_02 ]
Skills
The working stack — Active Directory tradecraft, web attack surface, the tooling either side of it, and the detection view of the same techniques.
ACTIVE_DIRECTORY
Active Directory and infrastructure
- Kerberoasting
- AS-REP roasting
- RBCD
- AD CS abuse (ESC1–ESC8)
- DCSync
- NTDS.dit via DiskShadow
- Cross-forest trust abuse
- NTLM relay
- Credential spraying
- Pivoting & tunnelling
WEB_APPLICATION
Web application testing
- SQL injection
- XXE
- SSRF
- Insecure file upload
- Directory traversal
- Authentication bypass
- IDOR
- Command injection
- WordPress & custom CMS
- OWASP Top 10
OFFENSIVE_TOOLING
Offensive tooling
- Burp Suite Pro
- BloodHound / SharpHound
- Impacket
- Certipy
- NetExec
- BloodyAD
- Rubeus
- Evil-WinRM
- Responder
- Ligolo-ng
- Havoc C2
- Metasploit
- Nmap / RustScan
- ffuf / Gobuster
- Nikto
- Nuclei
- SQLMap
- Hashcat
DETECTION_FORENSICS
Detection and forensics
- Wireshark
- Volatility 3
- Memory & disk forensics
- MITRE ATT&CK mapping
- Living-off-the-land detection notes
LANGUAGES_PLATFORMS
Languages and platforms
- Python
- Bash
- PowerShell
- Rust
- Nix
- TypeScript
- SQL
- C++
- LaTeX
- Kali Linux
- NixOS
- Arch / Debian
- Windows
- macOS (ARM64)
PROFESSIONAL
Professional
- Penetration test reporting
- Methodical documentation
- Remediation advice
- Communicating risk to non-technical stakeholders
- Self-directed research
[ SECTION_03 ]
Labs
Practical security experience — two enterprise-grade Hack The Box Pro Labs cleared end to end.
-
Hack The Box · Pro Labs
Zephyr — Enterprise Active Directory
- Compromised a multi-domain enterprise Active Directory estate end to end, chaining relay attacks, credential spraying and certificate-template abuse to reach Domain Admin.
- Pivoted across segmented subnets to reach otherwise unreachable hosts, then crossed a forest trust boundary to complete the objective.
- Documented every attack path with its remediation in a structured write-up.
-
Hack The Box · Pro Labs
Dante — Full Network Compromise
- Fully compromised a segmented, multi-subnet network of 20+ hosts, gaining initial access through web application flaws and exposed services.
- Modified and developed public exploit code where off-the-shelf payloads failed, then moved laterally using harvested credentials.
- Escalated privileges on both Linux and Windows hosts through misconfiguration analysis.
[ SECTION_04 ]
Projects
Tooling built and maintained — a NixOS pentest platform, an OSINT engine, a living-off-the-land catalogue and the research site behind them.
-
Personal Project
IceBreaker — Declarative NixOS Pentesting Environment
- Designed and maintain a reproducible offensive-security environment that rebuilds a full tooling stack from one declarative configuration, removing setup drift between engagements.
- Carries the Honours Project into daily use, packaging tools missing from upstream repositories.
-
Personal Project · Open Source
Percival — Username & Email OSINT Tool
- Single Rust binary merging the WhatsMyName, Sherlock and Maigret databases into 5,700+ deduplicated sites.
- Re-checks every hit against a random canary username to flag false positives, and reports WAF, captcha and rate-limit blocks instead of counting them as misses.
- Pivots on handles found in profiles, checks the Wayback Machine for deleted accounts, and exports HTML, JSON, CSV and Graphviz reports.
-
Personal Project · Open Source
DAEMONBins — Living-off-the-Land Catalogue
- Merged GTFOBins, LOLBAS and WADComs into one catalogue of 2,885 techniques across 842 tools, each with its command, MITRE ATT&CK mapping, detection guidance and references.
- Authored 179 entries — 134 fact-checked WADComs additions and 45 techniques from 2024–2026 — with every record schema-validated at build time.
-
Personal Project · Research Site
daemon-sec.xyz & Cheatsheet Vault
- Publish lab and CTF write-ups behind a vault secured with Argon2id hashing, signed sessions, login throttling and security regression tests, alongside a payload obfuscation tool that pairs each encoding with the telemetry that detects it.
- Maintain 60 cheatsheets across 12 domains with offline search, plus PayloadsAllTheThings mirrors synced daily through CI and gated on build and tests.
- Practise the clear, reproducible reporting expected in client-facing work, and keep hands-on skills current through HackTheBox Seasons.
[ SECTION_05 ]
Education
BSc (Hons) Ethical Hacking at Abertay — NCSC-certified course, honours research on NixOS as an offensive platform.
BSc (Hons) Ethical Hacking
Abertay University · Dundee
- Period
- 19 September 2022 — 10 July 2026
- Award
- Second Class Honours, Upper Division (2:1)
- Accreditation
- Certified by the National Cyber Security Centre
- Graduated
- 10 July 2026
HONOURS PROJECT
“NixOS as a Kali Linux Alternative” — evaluated the viability of NixOS as a reproducible, declarative offensive security platform, benchmarking tooling coverage and deployment repeatability against Kali Linux.
Key modules
- Advanced Ethical Hacking (CMP320)
- Web App Pen Testing (CMP319)
- Advanced Digital Forensics (CMP416)
- Engineering Resilient Systems (CMP417)
- IoT & Cloud Secure Development (CMP408)
- Computer Networking 2 (CMP314)
- Mobile Development (CMP309)
Community
Active member of the Abertay Ethical Hacking Society throughout the degree. Attendee every year since 2022 at Securi-Tay, Europe's largest student-run security conference, hosted at Abertay University.
[ SECTION_06 ]
Certifications
Verifiable credentials, ledgered. Next up: HTB Certified Penetration Testing Specialist.
-
HackTheBox Pro Labs — Zephyr
Hack The Box
HTBCERT-033F77F2E0
40 CPE13 / 03 / 2026
Active Directory, privilege escalation, relay attacks, pivoting, password cracking, web application attacks.
-
HackTheBox Pro Labs — Dante
Hack The Box
HTBCERT-12A3F211A0
40 CPE02 / 2026
Penetration testing, exploit development, lateral movement, situational awareness, web application attacks.
-
CCNAv7: Introduction to Networks
Cisco Networking Academy · Dundee and Angus College
CCNA06 / 2022
Networking fundamentals, IPv4 & IPv6 addressing, switching and routing, Ethernet, network security.
-
SIA Door Supervisor Licence
Security Industry Authority
SIA2023
-
HTB Certified Penetration Testing Specialist
Hack The Box Academy
In progressNext
[ SECTION_07 ]
Employment
The work that ran alongside the degree.
-
Security Scotland Ltd
Security Officer / Door Supervisor
- Front-line physical security at high-footfall venues alongside full-time study, to strict licensing and reporting standards — Fat Sam's Dundee, Celtic FC and the NHS Covid testing site in Edinburgh.
- Named Employee of the Month for intervening in a public-safety incident, helping stop traffic and safely bring a distressed individual down from a bridge until police arrived.
- Built the composure, clear escalation and accurate written reporting that carry over directly to security incident handling.
[ SECTION_08 ]
References
Academic referees — reachable directly below.
Mr Ross Heenan
Teaching Fellow
Department of Cybersecurity and Computing
Abertay University
r.heenan@abertay.ac.uk
01382 308647
Mr Jamie O'Hare
Lecturer
Department of Cybersecurity and Computing
Abertay University
j.ohare@abertay.ac.uk
01382 308248
linkedin.com/in/oharejamie