ctxzero Open to work
CTX-0 Offensive Security · Europe

ctxzero

Penetration Tester  /  Security Researcher

I break web applications, networks and Active Directory to understand how attacks actually work - then write it down so someone else can reproduce it. Manual first, tooling second, always chasing the why behind an exploitable finding.

Scroll
01DossierWho is behind the handle

Offensive security,the long way round.

I'm Luis - ctxzero online. Penetration tester and security researcher, based in Europe, working across web application, network and Active Directory offensive security.

I work manual-first and back it with the right tooling. A scanner flag is a starting point, not a finding - what matters is why something is exploitable, what it chains into, and what it actually costs the business when someone walks that path end to end.

Everything I learn ends up in two places: writeups that document the full route from recon to root, and tooling I build when the existing option is too slow or too loud. I'm pushing deeper into web application security and starting to work the other side of the fence - blue team and forensics - because knowing how detection fails makes for better offense.

FocusWeb application · Network · Active Directory
ApproachEnumerate everything. Verify by hand. Prove impact.
CurrentlySharpening web app skills · moving into blue team & forensics
TeamCo-captain @ v1olet - offensive security research & CTF
BasedEurope
StatusOpen to opportunities
-
Machines documented
04
Certifications held
03rd
BroncoCTF · 1065+ teams
28th
Cyber Apocalypse · 7k+ teams
02Capability matrixHover a technique for detail

Where I operate.

Grouped the way an engagement actually runs - from first packet to the report. Every cell is something I've used against a real target, not a bullet point off a syllabus.

Recon

Web app

Network

Active Directory

Post-ex

Tooling

Select Hover or tap any technique - the detail lands here.
03Engagement flowHow the work runs

Same four phases,every single time.

PHASE 01

Recon

Map the whole attack surface before touching anything. The finding that matters is usually on the host nobody remembered was in scope.

PHASE 02

Exploitation

Verify by hand, then chain. Individually low-severity issues become the interesting part once they stack.

PHASE 03

Post-exploitation

Escalate, pivot and demonstrate impact - because "we got a shell" is not a risk statement anyone can act on.

PHASE 04

Reporting

Reproducible steps, evidence, real business impact and remediation that fits how the team actually ships.

04ArsenalThings I built
Python · Tooling

PortHunt

A high-speed asynchronous port scanner with built-in CVE lookup and JSON/HTML reporting. Built because I wanted enumeration output that walks straight into a report instead of needing twenty minutes of reformatting first.

PythonAsyncCVE lookup JSON / HTML outputScriptable
ctxzero@ctx0 - porthunt
ctxzero@ctx0:~$ porthunt --target 10.10.11.42 --top 1000 --cve --report html

  +-- PORTHUNT ----------------------------------+
  |  fast async scanning · cve lookup · reports  |
  +----------------------------------------------+

[*] target      10.10.11.42
[*] range       top-1000 · 512 workers · 1.5s timeout
[*] started     14:02:11 UTC

[+]   22/tcp   open   ssh        OpenSSH 8.9p1 Ubuntu 3
[+]   80/tcp   open   http       nginx 1.18.0
[+]  445/tcp   open   smb        Samba 4.15.13
[+] 3306/tcp   open   mysql      MySQL 8.0.32

[!] CVE-2023-0286   high   X.400 address type confusion
[!] CVE-2022-38023  crit   Netlogon RPC signing downgrade

[OK] 4 open · 2 cve · 8.42s  ->  porthunt-10.10.11.42.html
ctxzero@ctx0:~$ 
05Field notesLoading…

Recon to root,written down.

Hack The Box machine writeups, pulled live from the repo and rendered right here - full route, every wrong turn included. Pick one.

Source
06Teamv1olet

Co-captain@ v1olet.

An independent offensive security research team - penetration testing, red team operations and vulnerability research.

We compete internationally as a CTF team. As co-captain I run the organisational side - roster, which events we play, how we split the board - and I play the competitions myself alongside everyone else. Different pressure than a lab box, and the best training there is.

Best finish · BroncoCTF
03of 1065+ teams

Podium on our first event together

The first competition we played as a team, straight onto the podium against a field of more than a thousand. Categories split across the roster: web, pwn, rev, crypto, forensics, osint, misc and beginner.

CTFtime
28th
HTB Cyber Apocalypse

28th out of 6,700+ teams

Hack The Box's global CTF and the largest field we've entered.

07CredentialsIndependently verifiable

Certifications.

CPTS badge - Hack The Box

Certified Penetration Testing Specialist

Hack The Box · CPTS

A ten-day, fully hands-on exam: blackbox web, external and internal penetration testing against a real Active Directory network in HTB's infrastructure over VPN. It starts with a letter of engagement setting out objectives, requirements and scope - and ends with a commercial-grade penetration test report. CPTS grades the testing and the communication of findings, which is exactly the part most certifications skip.

Verified Credly ↗
eJPT badge

eJPT

INE / eLearnSecurity
Verify ↗
ArcX Cyber Threat Intelligence badge

Cyber Threat Intelligence

ArcX · CTI101

LLM Security Expert

Red Team Leaders · CLLMSE

Web Exploitation Specialist

Hack The Box · CWES
In progress
08ContactResponse within a day

Got somethingworth breaking?

Engagements, collaboration, research, or a CTF roster that needs another pair of hands - all of it is welcome.