Penetration Tester

0xdf Portfolio

Maintains one of the most extensive public HackTheBox writeup archives in the community, with detailed walkthroughs covering Windows Active Directory attack chains, ADCS abuse, Kerberos exploitation and web application exploitation, published consistently for years.

HackTheBoxActive DirectoryCTF WriteupsPrivilege Escalation

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

Consistent, dated writeup format across hundreds of machines

Every writeup follows the same structure (recon, foothold, privesc, sometimes "beyond root"), making the archive genuinely useful as a reference rather than a one-off brag post — the format itself is part of the portfolio's value.

2

Coverage of advanced, current attack chains, not just beginner boxes

Recent posts cover ADCS certificate abuse and Kerberos exploitation — topics that map directly onto real enterprise Active Directory penetration tests, not just CTF trivia.

3

A public archive that functions as a searchable knowledge base

Cheatsheets and a large indexed post history mean the site serves other practitioners as a reference tool, not just a personal trophy case — which is what makes it widely linked across the security community.

What Penetration Testers can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • Use a consistent structure across every writeup (recon, foothold, privesc) so your archive becomes a reference tool, not just a series of one-off posts.

  • Cover advanced or currently-relevant techniques (like AD certificate abuse), not only beginner content — it signals your skills are current.

  • A large, well-organized public archive of real work is itself the portfolio; you don't need a separate 'projects' page if the writeups carry that weight.

Ready to build your portfolio?

Follow the Penetration Tester roadmap — skills, projects, and timeline to get hired.

Penetration Tester Roadmap