FILE :: CV — 2026OPEN_TO_OPPORTUNITIES

LEIF R. BRUCE

Penetration Testing · Offensive Security · SOC — Active Directory exploitation, web application testing and offensive tooling. [REDACTED], Scotland.

HTB rank
Master
Pro Labs cleared
2
CPE credits
80
Honours degree
2:1

[ SECTION_01 ]

Intro

Ethical Hacking graduate looking for a first role in offensive security or a SOC — the profile in brief.

whoami --full

role   :: junior penetration tester / red team / SOC analyst
focus  :: active directory · web application · offensive tooling
degree :: BSc (Hons) Ethical Hacking — 2:1, NCSC certified
htb    :: Master · level 65 — Zephyr, Dante Pro Labs, 80 CPE
next   :: HTB CPTS
loc    :: [REDACTED], Scotland
# status: available for junior pentest / red team / SOC roles

I'm an Ethical Hacking graduate from Abertay University — a degree certified by the National Cyber Security Centre — looking for a first role in offensive security or a SOC.

I hold Hack The Box Master rank at level 65, with the Zephyr and Dante Pro Labs completed — 80 CPE credits combined. Zephyr is where most of my Active Directory experience comes from: relay attacks, pivoting, password attacks, privilege escalation and crossing trust boundaries across a multi-domain estate. I play HTB Seasons to keep my enumeration sharp between labs, and CPTS is my next certification.

I also build my own tooling. My Honours Project asked whether NixOS could replace Kali Linux as a reproducible, declarative offensive platform; IceBreaker is the environment that came out of it. Percival is a Rust OSINT tool covering 5,700+ sites, and DAEMONBins merges GTFOBins, LOLBAS and WADComs into one catalogue. Everything I learn gets written up publicly at daemon-sec.xyz.

I care as much about the report as the shell — clear, reproducible write-ups a client can act on.

mailsorters_petrol_9@icloud.com webdaemon-sec.xyz gitDAEMON-404 htbprofile pgpon request

[ SECTION_02 ]

Skills

The working stack — Active Directory tradecraft, web attack surface, the tooling either side of it, and the detection view of the same techniques.

ACTIVE_DIRECTORY

Active Directory and infrastructure

  • Kerberoasting
  • AS-REP roasting
  • RBCD
  • AD CS abuse (ESC1–ESC8)
  • DCSync
  • NTDS.dit via DiskShadow
  • Cross-forest trust abuse
  • NTLM relay
  • Credential spraying
  • Pivoting & tunnelling

WEB_APPLICATION

Web application testing

  • SQL injection
  • XXE
  • SSRF
  • Insecure file upload
  • Directory traversal
  • Authentication bypass
  • IDOR
  • Command injection
  • WordPress & custom CMS
  • OWASP Top 10

OFFENSIVE_TOOLING

Offensive tooling

  • Burp Suite Pro
  • BloodHound / SharpHound
  • Impacket
  • Certipy
  • NetExec
  • BloodyAD
  • Rubeus
  • Evil-WinRM
  • Responder
  • Ligolo-ng
  • Havoc C2
  • Metasploit
  • Nmap / RustScan
  • ffuf / Gobuster
  • Nikto
  • Nuclei
  • SQLMap
  • Hashcat

DETECTION_FORENSICS

Detection and forensics

  • Wireshark
  • Volatility 3
  • Memory & disk forensics
  • MITRE ATT&CK mapping
  • Living-off-the-land detection notes

LANGUAGES_PLATFORMS

Languages and platforms

  • Python
  • Bash
  • PowerShell
  • Rust
  • Nix
  • TypeScript
  • SQL
  • C++
  • LaTeX
  • Kali Linux
  • NixOS
  • Arch / Debian
  • Windows
  • macOS (ARM64)

PROFESSIONAL

Professional

  • Penetration test reporting
  • Methodical documentation
  • Remediation advice
  • Communicating risk to non-technical stakeholders
  • Self-directed research

[ SECTION_03 ]

Labs

Practical security experience — two enterprise-grade Hack The Box Pro Labs cleared end to end.

  1. Hack The Box · Pro Labs

    Zephyr — Enterprise Active Directory

    March 202640 CPE

    • Compromised a multi-domain enterprise Active Directory estate end to end, chaining relay attacks, credential spraying and certificate-template abuse to reach Domain Admin.
    • Pivoted across segmented subnets to reach otherwise unreachable hosts, then crossed a forest trust boundary to complete the objective.
    • Documented every attack path with its remediation in a structured write-up.
  2. Hack The Box · Pro Labs

    Dante — Full Network Compromise

    February 202640 CPE

    • Fully compromised a segmented, multi-subnet network of 20+ hosts, gaining initial access through web application flaws and exposed services.
    • Modified and developed public exploit code where off-the-shelf payloads failed, then moved laterally using harvested credentials.
    • Escalated privileges on both Linux and Windows hosts through misconfiguration analysis.

[ SECTION_04 ]

Projects

Tooling built and maintained — a NixOS pentest platform, an OSINT engine, a living-off-the-land catalogue and the research site behind them.

  1. Personal Project

    IceBreaker — Declarative NixOS Pentesting Environment

    2025 — PresentNix · NixOS

    • Designed and maintain a reproducible offensive-security environment that rebuilds a full tooling stack from one declarative configuration, removing setup drift between engagements.
    • Carries the Honours Project into daily use, packaging tools missing from upstream repositories.
  2. Personal Project · Open Source

    Percival — Username & Email OSINT Tool

    September 2026Rust · OSINTgitlab.com/DAEMON-404/percival

    • Single Rust binary merging the WhatsMyName, Sherlock and Maigret databases into 5,700+ deduplicated sites.
    • Re-checks every hit against a random canary username to flag false positives, and reports WAF, captcha and rate-limit blocks instead of counting them as misses.
    • Pivots on handles found in profiles, checks the Wayback Machine for deleted accounts, and exports HTML, JSON, CSV and Graphviz reports.
  3. Personal Project · Open Source

    DAEMONBins — Living-off-the-Land Catalogue

    September 2026Astro · TypeScript · Zoddaemon-sec-lotl.vercel.app

    • Merged GTFOBins, LOLBAS and WADComs into one catalogue of 2,885 techniques across 842 tools, each with its command, MITRE ATT&CK mapping, detection guidance and references.
    • Authored 179 entries — 134 fact-checked WADComs additions and 45 techniques from 2024–2026 — with every record schema-validated at build time.
  4. Personal Project · Research Site

    daemon-sec.xyz & Cheatsheet Vault

    2024 — PresentReact · TypeScript · Express · Astrodaemon-sec.xyz · cheatsheet vault

    • Publish lab and CTF write-ups behind a vault secured with Argon2id hashing, signed sessions, login throttling and security regression tests, alongside a payload obfuscation tool that pairs each encoding with the telemetry that detects it.
    • Maintain 60 cheatsheets across 12 domains with offline search, plus PayloadsAllTheThings mirrors synced daily through CI and gated on build and tests.
    • Practise the clear, reproducible reporting expected in client-facing work, and keep hands-on skills current through HackTheBox Seasons.

[ SECTION_05 ]

Education

BSc (Hons) Ethical Hacking at Abertay — NCSC-certified course, honours research on NixOS as an offensive platform.

BSc (Hons) Ethical Hacking

Abertay University · Dundee


Period
19 September 2022 — 10 July 2026
Award
Second Class Honours, Upper Division (2:1)
Accreditation
Certified by the National Cyber Security Centre
Graduated
10 July 2026

HONOURS PROJECT

“NixOS as a Kali Linux Alternative” — evaluated the viability of NixOS as a reproducible, declarative offensive security platform, benchmarking tooling coverage and deployment repeatability against Kali Linux.

Key modules

  • Advanced Ethical Hacking (CMP320)
  • Web App Pen Testing (CMP319)
  • Advanced Digital Forensics (CMP416)
  • Engineering Resilient Systems (CMP417)
  • IoT & Cloud Secure Development (CMP408)
  • Computer Networking 2 (CMP314)
  • Mobile Development (CMP309)

Community

Active member of the Abertay Ethical Hacking Society throughout the degree. Attendee every year since 2022 at Securi-Tay, Europe's largest student-run security conference, hosted at Abertay University.

[ SECTION_06 ]

Certifications

Verifiable credentials, ledgered. Next up: HTB Certified Penetration Testing Specialist.

  • HackTheBox Pro Labs — Zephyr

    Hack The Box

    HTBCERT-033F77F2E0

    40 CPE

    13 / 03 / 2026

    Active Directory, privilege escalation, relay attacks, pivoting, password cracking, web application attacks.

  • HackTheBox Pro Labs — Dante

    Hack The Box

    HTBCERT-12A3F211A0

    40 CPE

    02 / 2026

    Penetration testing, exploit development, lateral movement, situational awareness, web application attacks.

  • CCNAv7: Introduction to Networks

    Cisco Networking Academy · Dundee and Angus College

    CCNA

    06 / 2022

    Networking fundamentals, IPv4 & IPv6 addressing, switching and routing, Ethernet, network security.

  • SIA Door Supervisor Licence

    Security Industry Authority

    SIA

    2023

  • HTB Certified Penetration Testing Specialist

    Hack The Box Academy

    In progress

    Next

[ SECTION_07 ]

Employment

The work that ran alongside the degree.

  1. Security Scotland Ltd

    Security Officer / Door Supervisor

    2023 — 2024SIA-licensed

    • Front-line physical security at high-footfall venues alongside full-time study, to strict licensing and reporting standards — Fat Sam's Dundee, Celtic FC and the NHS Covid testing site in Edinburgh.
    • Named Employee of the Month for intervening in a public-safety incident, helping stop traffic and safely bring a distressed individual down from a bridge until police arrived.
    • Built the composure, clear escalation and accurate written reporting that carry over directly to security incident handling.

[ SECTION_08 ]

References

Academic referees — reachable directly below.

Mr Ross Heenan

Teaching Fellow
Department of Cybersecurity and Computing
Abertay University

r.heenan@abertay.ac.uk
01382 308647

Mr Jamie O'Hare

Lecturer
Department of Cybersecurity and Computing
Abertay University

j.ohare@abertay.ac.uk
01382 308248
linkedin.com/in/oharejamie