CompTIA A+ Certified
CompTIA Security+ Certified

Break in first. Fortify everything after.

Breaking things to make them stronger: I dig into web and cloud systems to uncover flaws, weaponize exploits, and then turn them into defenses. Check out my recent red team projects, CTF write-ups, and security tools—I’m always pushing to learn more.

1
Projects
28
CTF writeups
24/7
Incident-ready mindset
Active engagement

Purple-team exercises with live detections shipping every sprint.

Signal strength+ Rapid TTP prototyping+ Threat-informed prioritization

Security with momentum

These are the disciplines I rotate through every week to turn offensive insight into resilient defenses.

Explore interests

Adversary Emulation

Designing bespoke attack chains that mirror the latest threat actors to pressure-test every defensive layer.

Detection Engineering

Building resilient detections, purple-team playbooks, and live dashboards that convert findings into action.

Security Research

Pulling apart binaries, cloud misconfigs, and web stacks to surface overlooked exploits before attackers do.

About

Security+ and A+ certified — though the certs came after the obsession, not before. Most of my time goes into understanding how attacks actually land, building tools to automate the parts of security work nobody wants to do by hand, and writing up findings so the next person doesn't have to start from scratch.

Python is where most of my tooling lives. C++ when speed matters, TypeScript when it needs a frontend. I try to build things that solve real problems — job market scraping with fake-listing detection, dark web OSINT crawlers, business audit automation — not just demo projects that look good in a README.

I spend time on HackTheBox and TryHackMe because there's no shortcut to learning offense. The writeups here are equal parts notes-to-self and resource for whoever's stuck on the same box.

B0bTheSkull on GitHub

Quick facts

CompTIA Security+
CompTIA A+
Active on HackTheBox
Active on TryHackMe
Python · C++ · TypeScript
OSINT & dark web research
Service Spotlight

Security Sanity Check for Small Teams

Find exposed risks, misconfigurations, and suspicious behavior without enterprise tools or alert spam. A focused, human-led review that gives you clarity fast.

Asset exposure sweep + misconfig audit
Credential hygiene and access review
Lightweight threat-hunt pass
Prioritized fix list with quick wins
What you get5-10 business days
Executive snapshot of the top risks and why they matter.
Evidence-backed findings with exact remediation steps.
Follow-up call to answer questions and align next steps.
Ideal for startups, small agencies, and lean product teams shipping fast.
Red TeamingAdversary SimulationCloud SecurityDetection EngineeringThreat HuntingMalware AnalysisOffensive ToolingRed TeamingAdversary SimulationCloud SecurityDetection EngineeringThreat HuntingMalware AnalysisOffensive Tooling

Latest Works

All projects
Project
Evil Twin Attack Simulation & Rogue Access Point Detection (ESP32)

Evil Twin Attack Simulation & Rogue Access Point Detection (ESP32)

This project explores how evil twin Wi-Fi attacks operate on a technical level by building a controlled, ethical simulation using ESP32 hardware. The goal was not to "hack Wi-Fi" but to deeply understand how threat actors exploit trust in wireless networks, and how defenders can detect and better mitigate these threats.

Battle-tested workflow

Every engagement is engineered as a story arc—intelligence-gathering, simulated impact, and hardening. Here’s how I keep teams engaged and outcomes measurable.

See it in practice
Stage 1

Recon & Discovery

Blend automated recon with human-led exploration to uncover forgotten assets, shadow services, and risky trust paths.

Surface the weak links
Stage 2

Weaponize & Simulate

Build tailored payloads, C2 frameworks, and signal-rich telemetry to replay the breach scenarios that keep teams awake.

Pressure-test controls
Stage 3

Harden & Share

Deliver concise remediation roadmaps, detection-as-code, and enablement workshops so teams can respond with confidence.

Ship actionable defense