0xdf Portfolio
Maintains one of the most extensive public HackTheBox writeup archives in the community, with detailed walkthroughs covering Windows Active Directory attack chains, ADCS abuse, Kerberos exploitation and web application exploitation, published consistently for years.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Consistent, dated writeup format across hundreds of machines
Every writeup follows the same structure (recon, foothold, privesc, sometimes "beyond root"), making the archive genuinely useful as a reference rather than a one-off brag post — the format itself is part of the portfolio's value.
Coverage of advanced, current attack chains, not just beginner boxes
Recent posts cover ADCS certificate abuse and Kerberos exploitation — topics that map directly onto real enterprise Active Directory penetration tests, not just CTF trivia.
A public archive that functions as a searchable knowledge base
Cheatsheets and a large indexed post history mean the site serves other practitioners as a reference tool, not just a personal trophy case — which is what makes it widely linked across the security community.
What Penetration Testers can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
Use a consistent structure across every writeup (recon, foothold, privesc) so your archive becomes a reference tool, not just a series of one-off posts.
Cover advanced or currently-relevant techniques (like AD certificate abuse), not only beginner content — it signals your skills are current.
A large, well-organized public archive of real work is itself the portfolio; you don't need a separate 'projects' page if the writeups carry that weight.
More Penetration Tester portfolios
Ready to build your portfolio?
Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.