About
whoami
I’m 0x5h4q — an 18-year-old self-taught security researcher with a focus on penetration testing. No bootcamp, no professor. Just me, a laptop, and a need to understand how things break. (I use Arch btw… haha <._.>)
Everything I know comes from hands-on learning outside of my formal university curriculum.
Experience
I’ve spent the past year and a half across HackTheBox, TryHackMe, PortSwigger Web Academy, and PicoCTF — building real skills through real challenges.
Active Directory & Internal Pentesting
My HackTheBox work focuses on machines that
replicate real corporate threat scenarios —
Active Directory exploitation, credential
harvesting via SSH honeypots, ACL abuse,
and network enumeration.
Web Application Security
Through PortSwigger Web Academy I’ve worked
hands-on through the OWASP Top 10, building
a foundation for bug bounty hunting.
CTF & Fundamentals
PicoCTF sharpened my fundamentals across binary
exploitation, file forensics, cryptography,
and reverse engineering.
Scripting & Automation
Python and Bash for security tooling and automation.
Hardware
Built and flashed a custom ESP32 Marauder device from scratch — hands-on experience with wireless attack frameworks and embedded hardware.
Tools I’ve Written
A few offensive tools on my GitHub:
- DNS Enumeration Tool — Python, comprehensive DNS record lookups with error handling
- Keylogger — Screenshot capability, process hiding, keystroke logging to file
Certifications & Stats
| PJPT | Practical Junior Penetration Tester |
| TryHackMe | Top 6% globally · 100+ labs |
| HackTheBox | VIP+ · Medium machines |
| PicoCTF | Active competitor |
Contact
- GitHub: github.com/0x5h4q
Breaking things. Writing about it. Repeat.