// whoami

The hunter behind the writeups

I'm thedevilhunter — an offensive security researcher who spends far too many nights rooting boxes and breaking web apps. This site is where I document the hunt: Hack The Box and TryHackMe machines, CTF challenges, and the occasional deep-dive into a technique or tool I couldn't find a good writeup for.

Every writeup here follows the same discipline I use on a real engagement: recon everything, understand why the exploit works before firing it, and document the path so clearly that someone else could walk it blind. No skipped steps, no "and then I got root."

The blade doesn't matter. The discipline of the cut does. — the mindset I bring to every box.

Arsenal

Recon & enum
nmapffufgobusterautoreconbloodhound
Web
Burp Suitesqlmapsstixssjwt
AD / Windows
impacketcrackmapexeckerberoastingevil-winrm
Privesc
linpeaswinpeasGTFOBinspspy
Cracking
hashcatjohnhydra

Path so far

2026 — now

Publishing writeups & research

Documenting boxes, CTFs and vulnerability research here at thedevilhunter.

2025

Grinding Hack The Box & ProLabs

Working through Active Directory attack paths and chaining real-world CVEs.

2024

Foundations

TryHackMe learning paths, web fundamentals, and the first taste of CTF.

Certs & goals

  • In progress: OSCP — working through the labs and stacking writeups.
  • Next up: CRTO / red-team tradecraft.
  • Always: one new box a week, documented properly.