Available for opportunities

Breaking things,
learning everything.

Web penetration tester and security researcher. I document exploits, write-ups, and hard-won lessons from CTFs, labs, and real assessments.

CRTA API Tester BSCP <- in progress OSCP -> next
Vali
Vali
$ whoami -> pentester
14 posts
5 certs
HTB active
THM active

About

I'm a university student focused on building a career in offensive security and penetration testing.

I'm currently in an intensive learning phase, working toward the Burp Suite Certified Practitioner (BSCP) while developing the practical skills required for OSCP-level work.

This blog serves as a record of that journey - documenting CTF write-ups, lab walkthroughs, and technical breakdowns of real-world attack techniques and tools.

Outside of that, I spend most of my time writing Python for automation, working through TryHackMe labs, and solving challenges on Hack The Box to strengthen my hands-on capabilities.

Certifications

Recent Posts

HackTheBox Devhub Walkthrough Shell

A ready-to-fill walkthrough shell for Devhub from Season 11: Season of the Punk.

open draft shell
HackTheBox Lab Notes

A growing machine index for HackTheBox write-ups, starting with Devhub from Season 11.

open hub
TryHackMe Valley: Complete Walkthrough

The full attack path from Nmap and web leaks to PCAP credentials, binary reversing, and a root cron-job module hijack.

read walkthrough
PortSwigger Authentication Labs

A growing screenshot-led walkthrough covering username enumeration and a simple 2FA bypass.

read post
TryHackMe Lab Notes

A growing room index for recon-to-root write-ups, beginning with the completed Valley challenge.

open hub
PortSwigger SSTI Labs Write-Up

A screenshot-driven walkthrough of PortSwigger's SSTI labs, covering engine fingerprinting, sandbox disclosures, object abuse, and custom exploit building.

read post
PortSwigger JWT Labs Write-Up

A Burp-first walkthrough of PortSwigger's JWT labs, covering none-alg abuse, weak secrets, header injection, and algorithm confusion without Python automation.

read post
Frankenstein NAS Build

A zero-cost home NAS built from an old router and a powered 1TB drive, including Windows 11 SMB fixes, mobile access, and the limits of a LAN-only setup.

read post
View all posts ->

Contact

GH
GitHub
@AryanSecOps
@
Email
aryan.malhotra.security@gmail.com