$ whoami
My name is Malachi Grimes, I'm a hacker. It's been my passion since I was little. Through a lot of hard work and a little luck I now have nearly half a decade of experience working in cybersecurity.
$ history
I got into hacking at a young age. Shortly after recieving my first computer, I used a UAC bypass (of course I didn't know that's what it was called) in Windows 7 to reset my parents' admin password and download games. That was my hook, from there I learned python and switched to daily-driving linux. Eventually I got into the OverTheWire CTFs and later TryHackMe. I've never stopped learning.
$ cat ~/skills.txt
Offensive Security
I've been on an unending warpath for years now, learning everything I can about offensive security. I reached top 2% in TryHackMe before shifting my focus to bigger things such as my OSCP and my still in-progress OSED. In my journey I have become proficient in:
- Active Directory Pentesting with tools like Bloodhound and the Impacket suite.
- Lateral Movement and network pivoting via tools like Ligolo.
- Privilege Escalation on both Windows and Linux using exploits or found/cracked credentials.
- Target Recon with tools like nmap, gobuster, nbtscan and more.
- Using Public Exploits as well as creating/modifying my own.
- Much more!
Exploit Development
Exploit Development and Vulnerability Research has become my main security interest as of late. Digging deep into systems and applications to discover flaws hidden deep in the code is a blast. I'm currently working on my OffSec Exploit Developer (OSED) certification and have been putting in the hours to get as good as I can. Some of the things I've learned include:
- Dynamic analysis and debugging with GDB and WinDbg
- Static reverse-engineering with Ida and Ghidra.
- Writing custom shellcode in x86 and x64 assembly.
- Identifying memory corruption vulnerabilities.
- Identifying logic bugs like checksum bypasses.
- I have a repo of exploits I've re-written as learning excersizes while playing CTFs.
Scripting and Programming
I have developed a solid understanding of programming in languages like Python, C, Lua, and more. While I'm no software engineer, I have written a lot of tools and fun applications over the years.
- Group Policy Password Decryptor - A tool to decrypt credentials found within Group Policy files using a known key.
- Katz^2 - a parser that turns Mimikatz credential dumps into ready-to-use files for Hashcat.
- Borg - A wrapper to make the Proxmox3 easier to use for reading writing and cloning RFID and NFC tags and cards. Specifically meant for subdermal implants.
- I've also written countless video game mods, Minecraft server tools, even a Discord bot that plays blackjack
Additional skills, click to learn more!
Adversary Emulation
Involvement in real world adversarial emulation projects.
Linux
Extensive understanding of linux and its workings.
Malware Analysis
Experience handling and analyzing live malware.
Digital Forensics and Incident Response
Hands-on experience with handling cybersecurity incidents.
Threat Intelligence
Knowledge of compiling and maintaining threat profiles.