Penetration Tester · CPTS Candidate
Joe Thompson
Offensive Security · Security Assessments · Reporting
I document real-world security assessments — from initial access to privilege escalation — with an emphasis on clear methodology and actionable reporting. This site highlights HTB box walkthroughs, selected portfolio reports, and my working pentest methodology.
-
SysReptor on Proxmox LXC
Deployed SysReptor in a Docker-inside-LXC container on Proxmox — lightweight dedicated reporting environment with persistent storage, accessible from anywhere on the lab network.
-
GPU-Accelerated Hash Cracking Station
Built a dedicated hash cracking VM with PCIe passthrough on Proxmox — IOMMU configuration, vfio-pci kernel binding, and RTX 2080 Ti passthrough to an isolated Ubuntu VM running Hashcat.
-
CPTS Pentest Methodology
Why the standard pentest lifecycle format didn't work for me during the CPTS exam — and what I built instead.
-
Archwarden — Security Portfolio Site
A self-built security portfolio site for writeups, methodology docs, and project work — designed to be accessible to people learning the field, not just to impress other hackers.
-
HTB HTB: Forest
AS-REP Roasting recovers credentials for a service account with no Kerberos pre-authentication. Nested group membership through Account Operators gives WriteDACL over the domain, enabling a DCSync attack for full domain compromise.
-
HTB HTB: Trick
DNS zone transfer exposes a hidden payroll application vulnerable to SQL injection. File read via SQLi reveals a second vhost with an LFI vulnerability — exploited through a filter bypass with PHP-FPM running as the target user, leaking an SSH key. A writable fail2ban action directory and a NOPASSWD sudo rule finish the job.
-
HTB HTB: Jeeves
Unauthenticated Jenkins access leads to remote code execution. A KeePass vault stored on the host contains reusable credentials that enable pass-the-hash access to Administrator.
Featured
-
From Hollywood to Hacker
What Fifteen Years in TV Taught Me About Penetration Testing
The skills that made me good at producing television turn out to be the same ones that matter in security work. The tools are different. The job is surprisingly similar.
Recent Posts
-
14 Flags
What It Actually Takes to Pass the CPTS Exam
An honest account of the Hack The Box CPTS exam: what the experience is really like, what preparation actually matters, and what I took away from passing with 14 of 14 flags.