Independent security field notesOffense informs defense.

Luís Barros.

Break it.
Understand it.
Defend it.

I’m a security consultant working across threat detection, incident response, and CVE research. This is where I document the process.

02 / The archive

Field notes.

Every finding has a trail.
These are mine.

Investigation / project18 entries
01

HTB Silentium

Easy Linux machine. Flowise 3.0.5 email enumeration, CVE-2025-58434 password reset token leak, CVE-2025-59528 JS injection RCE and Gogs CVE-2025-8110 symlink privesc.

02

HTB PingPong

Insane Windows AD machine with bidirectional domain trust. ADCS ESC13, cross-domain gMSA abuse, JEA, RBCD, ESC4 and DCSync.

03

HTB KOBOLD

Medium Linux machine. CVE-2026-23744 MCPJam Inspector RCE, operator group exploitation and Docker socket escape to host root.

04

HTB — CCTV (Easy Linux)

Easy Linux machine featuring ZoneMinder SQL injection (CVE-2024-51482), bcrypt hash cracking, SSH access and MotionEye RCE (CVE-2025-60787) for privilege escalation.

05

HackTheBox — Pterodactyl

Hard Linux machine on openSUSE Leap 15.6. XFS filesystem vulnerability (CVE-2025-6018/6019), race condition exploitation and privilege escalation.

06

HackTheBox — Logging

Medium Windows machine featuring log analysis vulnerabilities, SMB enumeration and privilege escalation. Full attack chain covered.

07

HackTheBox Facts

Medium Linux machine. Camaleon CMS mass assignment (CVE-2025-2304), S3 credential leak via admin panel, SSH access and Ruby Facter code injection for root.

08

HTB WingData

WingData (Easy Linux). CVE Chain: CVE-2025-47812 → Hash extraction → SSH → CVE-2025-4517. Recon: open ports 22, 80, wingdata.htb redirects to ftp.wingdata.

09

TryHackMe Slingshot: I Watched an Attacker Steal a Customer Database in Real Time

Reconstructed a complete web attack from ELK logs. Nmap → Gobuster → Hydra → web shell → LFI → database dump. The whole attack took 50 minutes. Every single step left obvious traces.

10

TryHackMe John the Ripper: I Cracked 10 Passwords in 30 Minutes

Learned John the Ripper by cracking MD5, SHA1, SHA256, Whirlpool, NTLM hashes, plus ZIP files, RAR archives, and SSH keys. Everything fell to rockyou.txt.

11

CVE-2024–42327: Exploiting a Critical Zabbix SQL Injection in Production

A Real-World Security Assessment of a 9.9 CVSS Vulnerability. When I set out to assess the security of a client's Zabbix monitoring infrastructure...

12

TryHackMe ItsyBitsy: When 0.4% of Traffic is 100% Malicious

Found a compromised machine by doing the opposite of what I thought was right. The suspicious IP had only 2 events out of 1,482. Sometimes the quietest connection is the loudest alarm.

13

TryHackMe Benign: The Imposter Account That Almost Fooled Me

Spent 30 minutes analyzing Splunk logs before realizing the attacker used Amel1a (with a 1) instead of Amelia (with an i). Sometimes the quietest activity is the loudest red flag.

14

SOC Lab — Splunk SIEM

Production-grade SOC environment built on Splunk. Processed 18K+ security events, custom detection dashboards, correlation rules, and threat hunting queries aligned with MITRE ATT&CK.

15

ELK Security Lab

Full ELK stack (Elasticsearch, Logstash, Kibana) for security monitoring. OWASP Top 10 threat detection, custom Kibana dashboards, and log ingestion pipelines for web and endpoint telemetry.

16

Sentinel SOC Lab

Cloud-native SOC environment on Microsoft Sentinel. Automated incident response playbooks, KQL analytics rules, UEBA configuration, and threat intelligence integration on Azure.

17

Google Cybersecurity Portfolio

Hands-on capstone projects from the Google Cybersecurity Professional Certificate. Covers security frameworks, incident response, network analysis, Linux hardening, SQL security, and Python automation.

18

Elasticsearch Lab (ARM64)

Elasticsearch lab environment optimised for ARM64 architecture (Apple M2 Mac). Docker Compose setup for local security data indexing and search experimentation without x86 constraints.

Always learning. Always investigating.

Let’s talk security.