Welcome to my offensive security and penetration testing portfolio. This repository serves as a centralized knowledge base containing comprehensive, professional-grade security reports and step-by-step walkthroughs for various TryHackMe (THM) rooms and Capture The Flag (CTF) challenges.
Each report is structured to mirror real-world Vulnerability Assessment and Penetration Testing (VAPT) documentation, detailing reconnaissance, exploitation phases, privilege escalation vectors, and remediation strategies.
- TryHackMe Archangel Report — Web application exploitation and local file inclusion (LFI) to remote code execution (RCE).
- TryHackMe Boiler CTF Report — Enumeration via ftp/ssh, cracking legacy protocols, and privilege escalation.
- TryHackMe CMSPIT Report — CMS vulnerability analysis, database exploitation, and horizontal privilege scaling.
- TryHackMe Mr. Robot CTF Report — Classic web app hacking, WordPress enumeration, credential auditing, and privilege escalation.
- TryHackMe Poster Report — Database misconfiguration exploitation and post-exploitation mapping.
- TryHackMe PrintNightmare Report — Documenting and exploiting critical Windows print spooler vulnerabilities (CVE-2021-1675 / CVE-2021-34527).
- TryHackMe hackerNote Report — Advanced web application mapping, session hijacking parameters, and reverse shell deployment.
VAPT Reports | Web Application Hacking | Privilege Escalation (Linux/Windows) | Network Enumeration | Exploit Research