Archives: Projects
Projects
HTB Certified Wi-Fi Pentesting Expert (HTB CWEP)
Preparing for HTB CWEP through hands-on Wi-Fi security training.
Project URL: https://academy.hackthebox.com/preview/certifications/htb-certified-wi-fi-pentesting-expert
I am currently working toward the HTB Certified Wi-Fi Pentesting Expert (HTB CWEP) certification.
The path focuses on practical wireless security assessment, including Wi-Fi reconnaissance, authentication and encryption weaknesses, enterprise wireless environments, and professional reporting.
Official certification overview: HTB Certified Wi-Fi Pentesting Expert.
HTB Certified Offensive AI Expert (HTB COAE)
HTB Certified Offensive AI Expert (COAE), earned 2 July 2026
Project URL: https://profile.hackthebox.com/profile/019db6b4-5b83-73c6-8cc1-bd2cfd524c9d/certificate/HTBCERT-F24E3768E6
Earned the HTB Certified Offensive AI Expert (HTB COAE) certification on 2 July 2026.
The certification validates hands-on offensive AI security skills across LLM attack surfaces, prompt injection, model behavior, AI application abuse paths, and responsible assessment methodology for modern AI-driven systems.
Credential ID: HTBCERT-F24E3768E6
Home Server Lab Infrastructure
Bare-metal home-server foundation for isolated offensive-security labs.
Project URL: https://www.synology-forum.de/threads/das-synology-zuhause.31885/page-8
Overview
This project documents the home-server infrastructure behind my offensive-security labs. The setup is built around bare-metal lab hardware and isolated networks so I can run Active Directory environments, WiFi/security labs, payload-testing systems, monitoring, snapshots, and repeatable training scenarios safely.
What It Supports
- Bare-metal virtualization for realistic lab performance.
- Separate lab networks for AD, tooling, testing, and management.
- Reusable environments for Ludus, GOAT-style AD labs, Windows targets, and Linux attack workstations.
- Snapshot-based workflows for fast rebuilds and clean testing.
Outcome
The home server gives me a stable base for hands-on research, certification preparation, red-team practice, and controlled security testing without relying only on cloud labs or public targets.
Image reference: IMGP0008.JPG from the Synology Forum thread “Das Synology Zuhause”.
WiFi Hacking Labs
WiFiChallenge Lab practice for virtual wireless penetration testing.
Project URL: https://lab.wifichallenge.com/
Overview
My WiFi hacking labs are focused on practical wireless security testing with WiFiChallenge Lab, a virtual Wi-Fi penetration testing environment that runs without physical adapters. The lab supports hands-on practice around wireless reconnaissance, packet capture workflows, authentication weaknesses, configuration hardening, and reporting.
Focus Areas
- WiFiChallenge Lab scenarios for OPN, WEP, WPA2-PSK, WPA3-SAE, OWE, and Enterprise setups.
- Wireless reconnaissance and signal-mapping methodology.
- Packet capture and traffic analysis workflows.
- Documentation of risk, impact, and hardening recommendations.
Outcome
The lab strengthens my wireless assessment methodology and supports practical preparation for real-world WiFi security reviews, while keeping testing scoped to owned and authorized environments.
Image reference: WiFiChallenge Lab logo from lab.wifichallenge.com.
Payload Obfuscation Lab
Controlled Windows 11 Defender detection and obfuscation research.
Project URL: https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint
Overview
This lab focuses on payload obfuscation and detection behavior in a controlled Windows 11 environment. The purpose is not to publish bypass recipes, but to understand how modern endpoint protection reacts to common offensive techniques and how defenders can validate their controls.
Focus Areas
- Static and behavioral detection differences.
- Payload transformation and obfuscation concepts.
- Windows 11 Defender response testing in isolated lab conditions.
- Operational notes for safer red-team testing, documentation, and cleanup.
Outcome
The project improved my ability to reason about endpoint detections, reduce false assumptions during offensive testing, and communicate findings in a way that helps defenders strengthen their endpoint security posture.
Image reference: Microsoft Defender logo via Wikimedia Commons.
GOAT AD Hacking Lab
Ludus-powered Active Directory attack-path lab on bare-metal infrastructure.
Project URL: https://ludus.cloud/
Overview
GOAT is my self-hosted Active Directory hacking lab built with Ludus on a bare-metal server. The goal was to create a repeatable enterprise-style environment for practicing enumeration, privilege escalation, lateral movement, domain compromise paths, and reporting workflows without touching real production systems.
What I Built
- Bare-metal virtualization host for stable lab performance.
- Ludus-based deployment workflow for repeatable AD environments.
- Windows domain targets, attack workstations, and segmented lab services.
- Practice scenarios for AD enumeration, Kerberos abuse paths, credential exposure, privilege escalation, and post-exploitation validation.
Outcome
The lab gives me a controlled place to sharpen Active Directory tradecraft, test tooling, document findings, and rehearse realistic red-team and pentest workflows in a safe environment.
Image reference: Active-directory.svg by RRZEicons via Wikimedia Commons, CC BY-SA 3.0.
AI Red Teamer Job Role Path
AI Red Teamer
Project URL: https://academy.hackthebox.com/path/preview/ai-red-teamer
I completed the Hack The Box AI Red Teamer path and earned the AI ninja badge. The path covered practical AI security concepts, including prompt injection, adversarial AI, AI privacy, model evasion, LLM output risks, and defensive thinking around modern AI systems.
Focus areas: AI attack surfaces, LLM abuse cases, prompt injection, model behavior, and practical AI security testing.
Hack The Box: Grandmaster
Hack The Box Grandmaster
Project URL: https://profile.hackthebox.com/profile/019db6b4-5b83-73c6-8cc1-bd2cfd524c9d
I reached Hack The Box Grandmaster rank on the ADonisRian #DE profile. This milestone reflects long-term hands-on progress across Hack The Box machines, labs, Academy content, challenges, and practical offensive security training.
Profile: Level 91, Grandmaster rank.
OffSec Experienced Penetration Tester (OSEP)
Experienced Penetration Tester
Project URL: https://www.offsec.com/courses/pen-300/
The OffSec Experienced Penetration Tester (OSEP) was a focused three-month advanced exploitation project. It strengthened my ability to chain attacks in mature environments, work through evasive tradecraft, perform client-side attacks, tunnel and pivot through networks, and document complex attack paths clearly.
Focus areas: Windows exploitation, AV and application-control bypass concepts, client-side attacks, tunneling, pivoting, lateral movement, and reporting.
Hack The Box Pro Labs: Zephyr
Active Directory Enterprise Lab
Project URL: https://www.hackthebox.com/blog/professional-labs-zephyr
Hack The Box Pro Labs: Zephyr was a one-month enterprise lab focused on realistic Active Directory compromise. The lab strengthened my skills in enumeration, relay attacks, pivoting, web application weaknesses, privilege escalation, and moving across trust boundaries.
Focus areas: AD enumeration, exploitation chains, pivoting, relay attacks, lateral movement, and enterprise-style attack paths.