Comprehensive web application penetration test of the Hack Smarter e-commerce platform. 30 vulnerabilities identified — SQL injection, RCE, XSS, SSRF, CSRF, IDOR, and session management weaknesses — with a full attack chain from unauthenticated visitor to remote code execution.
In this project, I executed a custom, low profile mTLS C2 beacon on a fully patched Windows 11 endpoint that did not trigger Windows Defender. I then examined how this activity appeared across endpoint telemetry in Wazuh and network telemetry in Security Onion.
In this project, I executed a custom, low profile mTLS C2 beacon on a fully patched Windows 11 endpoint that did not trigger Windows Defender. I then examined how this activity appeared across endpoint telemetry in Wazuh and network telemetry in Security Onion.