// offensive security · penetration testing · research

Tyler Vaughan
Cybersecurity Portfolio

Welcome. I'm Tyler. I am an aspiring cybersecurity professional. This site is where I keep an evolving record of what I've worked on.

Recent writeups

all writeups →

HTB: Sandworm — SSTI to Root via Rust Crate Hijacking

A walkthrough of HackTheBox Sandworm, demonstrating a PGP-based SSTI foothold, lateral movement through Rust crate hijacking, and privilege escalation via CVE-2022-31214 in Firejail.

HTB: Forest — AS-REP Roasting to Domain Admin

A walkthrough of HackTheBox Forest, demonstrating an AS-REP roast → BloodHound → DCSync attack chain on a misconfigured Active Directory environment.

Recent posts

all posts →

My OSCP+ Journey: Preparation, Failure, and What Finally Got Me Certified

How I failed the OSCP, what I changed, and what I would tell someone earlier in that same process.

Why I'm building this site

A short note on why I'm investing in a personal site as I push toward an offensive security career.