cyber-path/
βββ π ctf/ # Capture The Flag writeups & solutions
β βββ π web/ # Web exploitation challenges
β βββ π pwn/ # Binary exploitation
β βββ π crypto/ # Cryptography
β βββ π reverse/ # Reverse engineering
β βββ π forensics/ # Digital forensics
β βββ π misc/ # Miscellaneous challenges
β
βββ π bug-bounty/ # Bug bounty findings & methodology
β βββ π reports/ # Anonymized report templates
β βββ π methodology/ # Recon & exploitation workflows
β
βββ π labs/ # Hands-on lab environments
β βββ π hackthebox/ # HackTheBox machines
β βββ π tryhackme/ # TryHackMe rooms
β βββ π portswigger/ # PortSwigger Web Security Academy
β
βββ π cloud-security/ # Cloud security research & tooling
β βββ π wiz-challenges/ # Wiz security challenges
β
βββ π certs/ # Certification study notes & labs
β
βββ π scripts/ # Custom tools & automation
β
βββ π docs/ # Methodology guides & cheatsheets
βββ index.html # π Portfolio (GitHub Pages)
Metric
Value
CTF Roots
105
HackTheBox
Hacker
TryHackMe
[0x9] MAGE
Focus
Web / API / Cloud
Languages
EN / ES
Challenge
Category
Platform
Difficulty
Status
Coming soon
β
β
β
π
Focus areas: IDOR / BOLA / BFLA Β· Auth & Session Β· SSRF-to-Cloud Β· API Security (REST/GraphQL)
#
Target
Severity
Type
Status
Coming soon
β
β
β
π
Notable Findings (sanitized)
Finding
Description
Tags
IDOR β privilege escalation
Object-level access control issue enabling cross-tenant access
idor api
Auth logic bypass
Inconsistent checks between UI and API endpoints
auth api
SSRF risk in import feature
Potential internal network access; cloud metadata hardening recommended
ssrf cloud
Machine / Room
Platform
Difficulty
Writeup
Coming soon
β
β
π
Challenge
Platform
Topic
Status
Coming soon
β
β
π
Cert
Status
Tags
Link
CCNA
β
Completed
Network Β· Routing Β· SDN
Credly
AWS Solutions Architect
β
Completed
Cloud Β· Architecture
Credly
Terraform Associate
β
Completed
IaC Β· Cloud
Credly
CompTIA Security+ 701
π In Progress
Cybersecurity Β· Defensive Β· GRC
Credly
HTB CPTS
π In Progress
Offensive Β· Web Β· AD
β
HTB CBBH
π In Progress
Offensive Β· Web Β· API
β
CRTO
π In Progress
Offensive Β· Red Team
β
OSCP
β³ Not started
Offensive
β
Path
Status
Tags
PortSwigger Web Security Academy
π Ongoing
Web
HTB Academy (CPTS, CBBH, ProLabs)
π Ongoing
Offensive
Cloud labs (AWS)
π Ongoing
Cloud
Each writeup follows a consistent format:
## Challenge Name
### Recon β Foothold β Privesc β Root
- π― Objective
- π Enumeration & Discovery
- π£ Exploitation
- π Flag / Proof
- π Lessons Learned
When
Goal
Detail
Now
Finish CPTS + consistent bug bounty routine
Daily reps: labs + target practice; write one note per week
3β6 months
Increase valid reports + focus specialization
Deepen access control expertise (BOLA/BFLA) across APIs
Next
Increase high/critical vulnerabilities found
Show proof: reports, certs, writeups, and professional workflow
If you find this repo useful, drop a β β it fuels the grind.