whoami

I’m 0x5h4q — an 18-year-old self-taught security researcher with a focus on penetration testing. No bootcamp, no professor. Just me, a laptop, and a need to understand how things break. (I use Arch btw… haha <._.>)

Everything I know comes from hands-on learning outside of my formal university curriculum.


Experience

I’ve spent the past year and a half across HackTheBox, TryHackMe, PortSwigger Web Academy, and PicoCTF — building real skills through real challenges.

Active Directory & Internal Pentesting
My HackTheBox work focuses on machines that replicate real corporate threat scenarios — Active Directory exploitation, credential harvesting via SSH honeypots, ACL abuse, and network enumeration.

Web Application Security
Through PortSwigger Web Academy I’ve worked hands-on through the OWASP Top 10, building a foundation for bug bounty hunting.

CTF & Fundamentals
PicoCTF sharpened my fundamentals across binary exploitation, file forensics, cryptography, and reverse engineering.

Scripting & Automation
Python and Bash for security tooling and automation.


Hardware

Built and flashed a custom ESP32 Marauder device from scratch — hands-on experience with wireless attack frameworks and embedded hardware.


Tools I’ve Written

A few offensive tools on my GitHub:

  • DNS Enumeration Tool — Python, comprehensive DNS record lookups with error handling
  • Keylogger — Screenshot capability, process hiding, keystroke logging to file

Certifications & Stats

   
PJPT Practical Junior Penetration Tester
TryHackMe Top 6% globally · 100+ labs
HackTheBox VIP+ · Medium machines
PicoCTF Active competitor

Contact


Breaking things. Writing about it. Repeat.