Offensive Security Case Studies
Adversarial security assessments covering cloud infrastructure, backdoor development, web applications, phishing operations, and full-scope penetration tests with structured reporting and MITRE ATT&CK mapping.
Azure Red Team — Cloud Infrastructure Assessment
Full-scope red team assessment of enterprise Azure infrastructure covering Azure AD enumeration, RBAC misconfigurations, managed identity abuse, storage account exposure, Key Vault assessment, and network security group reviews. 12 findings identified with 3 privilege escalation paths mapped to MITRE ATT&CK.
Backdoor Development — Custom Payload & C2 Analysis
Full-spectrum backdoor development project covering payload generation, process injection techniques (CreateRemoteThread, APC, process hollowing), multiple persistence mechanisms, HTTPS-based C2 with custom beaconing, and antivirus evasion via AMSI patching and ETW suppression.
Phishing Operations — Multi-Wave Campaign Design
Full-spectrum phishing operations project using GoPhish framework with four escalating campaign waves: generic phishing, spear-phishing with OSINT, CEO BEC simulation, and credential harvesting via cloned Office 365 login pages. Covered the complete social engineering kill chain.