ctxzero Open to work
CTX-0 Offensive Security · Europe

ctxzero

Penetration Tester  /  Security Researcher

I break web applications, networks and Active Directory to understand how attacks actually work - then write it down so someone else can reproduce it. Manual first, tooling second, always chasing the why behind an exploitable finding.

Scroll
01DossierWho is behind the handle

Offensive security,the long way round.

I'm Luis - ctxzero online. Penetration tester and security researcher, based in Europe, working across web application, network and Active Directory offensive security.

I work manual-first and back it with the right tooling. A scanner flag is a starting point, not a finding - what matters is why something is exploitable, what it chains into, and what it actually costs the business when someone walks that path end to end.

Everything I learn ends up in two places: writeups that document the full route from recon to root, and tooling I build when the existing option is too slow or too loud. I'm pushing deeper into web application security and starting to work the other side of the fence - blue team and forensics - because knowing how detection fails makes for better offense.

FocusWeb application · Network · Active Directory
ApproachEnumerate everything. Verify by hand. Prove impact.
CurrentlyMoving into blue team & forensics
TeamCo-captain @ v1olet - offensive security research & CTF
BasedEurope
StatusOpen to opportunities
-
Machines documented
05
Certifications held
02nd
Best CTF finish · 2× runner-up
28th
Cyber Apocalypse · 7,000+ teams
02Capability matrixHover a technique for detail

Where I operate.

Grouped the way an engagement actually runs - from first packet to the report. Every cell is something I've used against a real target, not a bullet point off a syllabus.

Recon

Web app

Network

Active Directory

Post-ex

Tooling

Select Hover or tap any technique - the detail lands here.
03Engagement flowHow the work runs

Same four phases,every single time.

PHASE 01

Recon

Map the whole attack surface before touching anything. The finding that matters is usually on the host nobody remembered was in scope.

PHASE 02

Exploitation

Verify by hand, then chain. Individually low-severity issues become the interesting part once they stack.

PHASE 03

Post-exploitation

Escalate, pivot and demonstrate impact - because "we got a shell" is not a risk statement anyone can act on.

PHASE 04

Reporting

Reproducible steps, evidence, real business impact and remediation that fits how the team actually ships.

04ArsenalThings I built
Python · Tooling

PortHunt

A high-speed asynchronous port scanner with built-in CVE lookup and JSON/HTML reporting. Built because I wanted enumeration output that walks straight into a report instead of needing twenty minutes of reformatting first.

PythonAsyncCVE lookup JSON / HTML outputScriptable
ctxzero@ctx0 - porthunt
ctxzero@ctx0:~$ porthunt --target 10.10.11.42 --top 1000 --cve --report html

  +-- PORTHUNT ----------------------------------+
  |  fast async scanning · cve lookup · reports  |
  +----------------------------------------------+

[*] target      10.10.11.42
[*] range       top-1000 · 512 workers · 1.5s timeout
[*] started     14:02:11 UTC

[+]   22/tcp   open   ssh        OpenSSH 8.9p1 Ubuntu 3
[+]   80/tcp   open   http       nginx 1.18.0
[+]  445/tcp   open   smb        Samba 4.15.13
[+] 3306/tcp   open   mysql      MySQL 8.0.32

[!] CVE-2023-0286   high   X.400 address type confusion
[!] CVE-2022-38023  crit   Netlogon RPC signing downgrade

[OK] 4 open · 2 cve · 8.42s  ->  porthunt-10.10.11.42.html
ctxzero@ctx0:~$ 
05Field notesLoading…

Recon to root,written down.

Hack The Box machine writeups, pulled live from the repo and rendered right here - full route, every wrong turn included. Pick one.

Source
06Teamv1olet

Co-captain@ v1olet.

An independent offensive security research team - penetration testing, red team operations and vulnerability research.

We compete internationally as a CTF team. As co-captain I run the organisational side - roster, which events we play, how we split the board - and I play the competitions myself alongside everyone else. Different pressure than a lab box, and the best training there is.

PlaceEventFieldPercentile
02nd
BrunnerCTFweb · pwn · rev · crypto · forensics
1,103 teams
Top 0.2%
02nd
0xVoid CTFweb · pwn · rev · crypto · forensics
500 teams
Top 0.4%
03rd
BroncoCTFFirst event we played as a team
1,065 teams
Top 0.3%
28th
HTB Cyber ApocalypseLargest field we have entered
7,000+ teams
Top 0.4%
Bar shows field size, log scale Full record on CTFtime ↗
07CredentialsIndependently verifiable

Certifications.

CPTS badge - Hack The Box

Certified Penetration Testing Specialist

Hack The Box · CPTS

A ten-day, fully hands-on exam: blackbox web, external and internal penetration testing against a real Active Directory network in HTB's infrastructure over VPN. It starts with a letter of engagement setting out objectives, requirements and scope - and ends with a commercial-grade penetration test report. CPTS grades the testing and the communication of findings, which is exactly the part most certifications skip.

Verified Credly ↗
CWES badge - Hack The Box

Certified Web Exploitation Specialist

Hack The Box · CWES

A hands-on web application exam against a live target: find the entry point, chain the findings into something with real impact, and document it in a commercial-grade report. The path covers modern surface properly - APIs and GraphQL alongside the classic injection and access-control work. Passed with a perfect score of 100/100, with the report graded excellent on impact and remediation. Issued as CBBH until October 2025, renamed with the move from the bug bounty path to web penetration testing.

100 / 100 Verified Credly ↗
eJPT badge

eJPT

INE / eLearnSecurity
Verify ↗
ArcX Cyber Threat Intelligence badge

Cyber Threat Intelligence

ArcX · CTI101

LLM Security Expert

Red Team Leaders · CLLMSE
08ContactResponse within a day

Got somethingworth breaking?

Engagements, collaboration, research, or a CTF roster that needs another pair of hands - all of it is welcome.