Archives: Projects
Projects
ZIP domains
Zip domains are not inherently a problem. However, if you are referring to “zip” as a term used to describe certain types of domains, such as those ending with “.zip” or containing the word “zip,” there are a few reasons why they can be problematic:
- Malicious Content: Files with the “.zip” extension are commonly used to compress multiple files into a single archive. While this format is often harmless, it can also be exploited to distribute malware, viruses, or other malicious content. Attackers may use deceptive filenames or disguise harmful files within a .zip archive, increasing the risk to unsuspecting users.
- Phishing Attempts: Cybercriminals frequently use deceptive domain names that include the term “zip” to trick users into thinking they are downloading legitimate files. They might imitate popular software or services, luring users to visit these domains and unknowingly expose their sensitive information or download harmful content.
- Reputation and Legitimacy: Some domains containing the term “zip” may have earned a reputation for hosting or promoting illegal or unethical activities. Such associations can tarnish the reputation of legitimate websites or businesses using similar domain names.
It’s important to note that the issues mentioned above are not exclusive to domains with the term “zip.” Malicious actors can use various tactics and techniques to exploit users, regardless of the domain name. It is crucial for individuals to exercise caution when downloading files or interacting with any online content, regardless of the domain. Employing reliable security practices, using up-to-date antivirus software, and being mindful of suspicious websites or downloads can help mitigate potential risks.
I have registered a domain called “sex-tape.zip” with the intention of demonstrating the potential dangers associated with such deceptive domain names. Just imagine receiving an email containing a URL like this! https://pornhub∕yourname∕lastname@sex-tape.zip
By creating this example, I aim to highlight the power and risks posed by these types of domains. It serves as a cautionary reminder of how easily unsuspecting individuals can fall victim to malicious schemes, such as phishing or malware attacks. The purpose is to educate and raise awareness about the importance of exercising caution online and being mindful of the potential threats that exist.
HTB Academy Student Transcript
HTB Academy progress, completed modules, learning paths, and certification-related work.
Project URL: https://academy.hackthebox.com/
This July 2026 transcript shows my current HTB Academy progress: three certifications (CPTS, CAPE, and COAE), six completed paths, 740 compromised targets, and a Top 1% Academy ranking.
It also documents the practical Wi-Fi training behind my current preparation for the HTB Certified Wi-Fi Pentesting Expert (HTB CWEP).
Download the current transcript: HTB Academy Student Transcript – July 2026.
Certified Penetration Testing Specialist (HTB CPTS)
Penetration Testing Specialist
Project URL: https://academy.hackthebox.com/preview/certifications/htb-certified-penetration-testing-specialist
The HTB Certified Penetration Testing Specialist (HTB CPTS) was a two-year practical learning path around end-to-end penetration testing methodology. It covered enumeration, exploitation, web attacks, privilege escalation, pivoting, Active Directory, and professional reporting before I passed the exam on 28 September 2025.
Focus areas: structured enumeration, web application attacks, Linux and Windows privilege escalation, Active Directory, pivoting, and report writing.
Hacking Lab (VM)
Virtual Machines
My secure network sandbox for practicing hacking skills and learning in a safe virtual machine environment is a custom-built lab designed to simulate real-world penetration testing scenarios. The lab includes an Active Directory (AD) environment along with intentionally vulnerable Windows and Linux machines, providing a comprehensive platform for honing offensive security techniques.
By setting up a controlled AD infrastructure, I am able to practice privilege escalation, lateral movement, and domain compromise strategies commonly encountered in enterprise environments. The vulnerable machines mimic common misconfigurations and security flaws, allowing me to experiment with a variety of attack vectors and develop remediation techniques. This hands-on experience has been invaluable in refining my skills in both network and system-level exploitation while ensuring all testing is performed in a safe, isolated environment.
Certified Red Team Professional (CRTP)
Certified Red Team Professional (CRTP)
Project URL: https://www.alteredsecurity.com/adlab
I am proud to announce that I successfully passed the **Certified Red Team Professional (CRTP)** exam on **October 18, 2024**. This certification is a testament to my expertise in attacking and exploiting Active Directory environments, focusing on advanced red teaming techniques, including privilege escalation, lateral movement, and bypassing security controls. The CRTP exam challenged me to apply my knowledge in real-world scenarios, further enhancing my ability to execute sophisticated attack paths and identify critical vulnerabilities within enterprise networks.