Certification

Certified Active Directory Pentesting Expert V2 (C-ADPENX)

Active Directory Pentesting Expert

Certified Active Directory Pentesting Expert V2 (C-ADPENX)
Company: The SecOps Group (C-ADPENX)
Project URL: https://pentestingexams.com/certifications/expert/certified-active-directory-pentesting-expert/

The Certified Active Directory Pentesting Expert V2 (C-ADPENX) was an intensive Active Directory exam from The SecOps Group. I completed it in May 2025 after focused preparation on enterprise attack paths, privilege escalation, lateral movement, and domain compromise techniques.

Certificate ID: 10072980. Exam version: 2.01.

Personal Security Blog

My Journey: A Personal Hacking Blog

Personal hacking blog with writeups, certification notes, and practical security learning updates.

My Journey: A Personal Hacking Blog
Project URL: https://blog.rian-friedt.de/

This blog is a project of mine to share what I’ve learned along the way.

Here, you’ll find write-ups of my hacking experiences, insights from penetration testing, and reviews of CAPE certification modules.

My goal is to document my journey and connect with others who share a curiosity for the ever-evolving world of digital security.

Feel free to explore, leave comments, or reach out. Thank you for stopping by, and I hope my insights and experiences inspire your own path in cybersecurity.

Certified Red Team Operator (CRTO)

Certified Red Team Operator (CRTO)
Company: Zero-Point Security (CRTO)

I am proud to announce that I successfully passed the Certified Red Team Operator (CRTO) exam on 4th of December, 2024. This certification is a testament to my expertise in attacking and exploiting Windows enterprise environments, focusing on advanced red teaming techniques and the use of industry-standard tools like Cobalt Strike. Cobalt Strike is widely used by red teams for simulating advanced persistent threats, enabling command-and-control operations, and facilitating complex attack methodologies such as privilege escalation, lateral movement, and bypassing security controls. The CRTO exam challenged me to apply my knowledge in real-world scenarios, further enhancing my ability to execute sophisticated attack paths and identify critical vulnerabilities within enterprise networks.

Mythic C2 Framework

Mythic C2 Framework
Project URL: https://docs.mythic-c2.net/

 

Currently, I am working on a project related to learning and applying the concepts of Command and Control frameworks, particularly Mythic, in executing pentesting and red team engagements. Mythic is an open-source C2 framework developed to mimic adversary activity. It’s a way for the offensive security team to have flexibility emulating an APT in a stealthy manner.

This project’s objective is to show deep knowledge about the C2 infrastructures, their purpose in post-exploitation activities, and how it could be used to simulate realistic attack scenarios during a security assessment. In developing a Mythic C2 environment and setting it within a simulated enterprise network, I am looking at a number of key elements:

  •  Initial Access and Persistence: Mythic is designed to provide support for different modular agents, such as Apollo or Poseidon, which can then emulate various types of payload to create footholds across target systems.
  • Command Execution and Data Exfiltration: It has the capability for remote execution of commands on the compromised machine, which keeps the control and surreptitiously exfiltrates sensitive data.
  • Defense Evasion: Realize advanced techniques to bypass detection mechanisms like AV, EDR solutions, or OS-level features; implement Mythic’s covert communication channels with HTTP/S, DNS, and other protocols.
  • Situational Awareness and Lateral Movement: C2 channels are used in order to gain intelligence, escalate privileges, and perform lateral movements across the network using evasion techniques.

In this project, I hope to show a good understanding of the knowledge of offensive security methodologies and point out how the use of C2 frameworks like Mythic will be able to provide a realistic attack scenario that would assist organizations in finding such weak links before malicious actors do.

Therefore, I will be equally focused on the technological expertise and strategic significance of the C2 frameworks while developing effectiveness in red team operations and proactive threat hunting. This experience shall provide me with more knowledge about Mythic and similar systems, especially insights into modern attacker behaviors that I can bring to security engagements later on.                                                                                                                                              

 

 

 

Dante Certificate (HTB)

Dante Certificate (HTB)
Project URL: https://www.hackthebox.com/hacker/pro-labs

I am proud to have completed the Dante HTB Pro Labs certification, an advanced and immersive experience designed to simulate real-world penetration testing in a fully realistic, enterprise-level environment. During this journey, I refined my skills in network enumeration, privilege escalation, lateral movement, and Active Directory exploitation. The Dante lab’s complex, multi-layered infrastructure challenged me to apply advanced offensive security techniques and develop a deeper understanding of red teaming strategies. This certification reinforced my ability to think critically, adapt to evolving challenges, and execute well-structured attack paths, making it invaluable for real-world penetration testing scenarios

OffSec Wireless Professional (OSWP)

OffSec Wireless Professional (OSWP)
Company: OffSec (OSCP/OSWP)
Project URL: https://www.offsec.com/courses/pen-210/

I am proud to have earned my Offensive Security Wireless Professional (OSWP) certification. This experience provided me with a deep understanding of wireless network security and hands-on expertise in attacking and defending WiFi networks. Throughout the process, I mastered techniques such as packet capture, wireless encryption cracking, and bypassing security mechanisms like WEP, WPA, and WPA2. The OSWP also reinforced critical problem-solving skills and taught me how to approach wireless security assessments with precision and a methodical approach.

OffSec Certified Professional (OSCP)

OffSec Certified Professional (OSCP)
Company: OffSec (OSCP/OSWP)
Project URL: https://www.offsec.com/courses/pen-200/

I am proud to have successfully earned my Offensive Security Certified Professional (OSCP) certification. It was an incredibly challenging yet rewarding experience that significantly enhanced my practical skills in penetration testing. Throughout the process, I gained hands-on expertise in areas such as network enumeration, vulnerability analysis, exploit development, and privilege escalation—key skills essential for real-world ethical hacking. The OSCP not only taught me how to think critically and solve complex problems under pressure, but it also reinforced the importance of persistence, creativity, and a structured approach to security challenges.

Youtube Channel

Youtube Channel
Project URL: https://www.youtube.com/@HackToBasic

I run my own YouTube channel where I demonstrate ethical hacking techniques in German, catering to a niche audience as there are very few German-language hacking tutorials available. On my channel, I showcase how to hack retired machines on platforms like Hack The Box and others, walking through each step of the process. My goal is to provide valuable content to German-speaking cybersecurity enthusiasts by breaking down complex penetration testing techniques in an accessible and engaging way.

Certification

HTB Certified Active Directory Pentesting Expert (HTB CAPE)

Active Directory Pentesting Expert

HTB Certified Active Directory Pentesting Expert (HTB CAPE)
Company: Hack the Box Academy (Active Directory Penetration Tester)
Project URL: https://academy.hackthebox.com/preview/certifications/htb-certified-active-directory-pentesting-expert

The HTB Certified Active Directory Pentesting Expert (HTB CAPE) was a long-term Active Directory certification project. I spent roughly one year building depth in Windows tradecraft, AD exploitation, lateral movement, privilege escalation, evasion-aware methodology, and reporting before passing the exam on 26 January 2026.

Focus areas: Active Directory attack paths, Kerberos, Windows internals, domain privilege escalation, lateral movement, and enterprise-style reporting.

HoneyPot

HoneyPot
Company:

I’m currently using a powerful honeypot called Tpot, provided by Telecom, to expose the constant barrage of hackers attempting to infiltrate servers from all corners of the globe. A honeypot is essentially a trap I’ve set up to attract these malicious individuals and observe their tactics in action. By live-streaming the activities of Tpot, I’m showcasing to the world just how relentless these hackers are and the ongoing battle we face in defending our servers.

Through this initiative, I aim to shed light on the ever-present threat of cyber attacks and raise awareness about the importance of robust cybersecurity measures. It’s an opportunity for everyone to witness firsthand the scale and diversity of these hacking attempts, ultimately empowering individuals and organizations to strengthen their defenses and stay vigilant against evolving threats.

 

https://www.youtube.com/@HackToBasic

!!!( VPS got taken down due to its high traffic and malicious traffic attracted to the honeypot )!!!