About

I am a junior penetration tester working on web applications and networks. I study by breaking lab machines on my own time — mostly TryHackMe rooms and the PortSwigger Web Security Academy — and I write up each one while it is still fresh.

The writeups here are lab notes, not client reports. They follow the order I actually worked in: what I observed, what I did, what came back, and what I would take from it next time. Where a step was not recorded while I was solving, the note says so instead of filling the gap in.

Before security I did IT and network engineering at Al Nour Tech from 2019 to 2021, then freelance web development until 2023. The security work grew out of that: I had been the person wiring up the networks and shipping the web apps, and then I wanted to know where they broke.

What is here

Elsewhere