▶ ECE Graduate · Penetration Tester · HTB Pro

Hack.
Exploit.
Sell.

Cybersecurity research, writeups & PoCs — plus tech services and a gear shop for the security community. All from one platform.

Penetration TestingHTB WriteupsTech ServicesGear Shop
Writeups
0
HTB Machines
0
THM Rooms
#0
HTB Global Rank
🔴
Cybersecurity Services

Penetration testing, security audits, staff training — for SMEs, SACCOs, schools and businesses.

Pentest · Audit · Training
🔵
Tech Services

Website design, CCTV, WiFi setup, Google Business, IT support and computer repair.

Websites · CCTV · IT Support
🟡
Shop — Gear & Hardware

Laptops, Flipper Zero, pentest tools, networking gear and KnightSec merch. M-Pesa accepted.

Laptops · Flipper Zero · Tools
// Writeups

Latest Research & Walkthroughs

Technical breakdowns of CTF challenges, HTB machines and real-world vulnerabilities. Active machine writeups are locked until retirement.

MediumLinux2 CVEs

DevArea — HackTheBox Writeup (Linux, Medium)

Anonymous FTP drops an Apache CXF JAR — WSDL analysis reveals a SOAP endpoint vulnerable to SSRF/LFI via MTOM (CVE-2022-46364). File read leaks Hoverfly credentials, and CVE-2025-54123 turns the dashboard into RCE.

2026-03-29🔒 Locked
EasyLinux2 CVEs

Kobold — HackTheBox Writeup (Linux, Easy)

Subdomain enumeration reveals MCPJam v1.4.2 vulnerable to unauthenticated RCE via CVE-2026-23744. A base64-encoded reverse shell bypasses filtering, and docker group access lets us mount the host filesystem to read root's flag.

2026-03-27🔒 Locked
MediumLinux

Browsed — HackTheBox Writeup (Linux, Medium)

A headless Chrome extension testing service enables browser-context SSRF to pivot into internal Gitea and Flask apps. Bash arithmetic expansion injection in a shell script delivers the reverse shell as larry.

2026-03-27🔒 Locked
MediumLinux1 CVE

Interpreter — HackTheBox Writeup (Linux, Medium)

CVE-2023-43208 gives unauthenticated RCE on Mirth Connect 4.4.0 via Java deserialization. DB credentials lead to a PBKDF2 hash crack for SSH as sedric, then an SSTI in a Flask notif service running as root closes the chain.

2026-03-21🔒 Locked
MediumLinux2 CVEs

VariaType — HackTheBox Writeup (Linux, Medium)

An exposed .git directory leaks hardcoded credentials, two CVEs in font processing libraries chain together for RCE as www-data then steve, and a sudo misconfiguration in setuptools lets you write an SSH key directly to /root/.ssh/authorized_keys.

2026-03-16🔒 Locked
EasyWindows

Eighteen — HackTheBox Writeup (Windows, Easy)

MSSQL impersonation pivots to a financial database where PBKDF2 hashes crack to domain credentials, then the badSuccessor RBCD technique chains through Kerberos to a full DCSync — every NTLM hash in the domain dumped.

2026-03-16Read →

3 writeups published · 5 locked

All writeups →
// Blog & News

Cybersec Intel, PoCs & Research

Weekly CVE breakdowns, threat intel, PoC exploits and security research that actually matters.

3 posts published

All posts →
// Services — Cybersecurity

Security Services

Professional penetration testing, security audits and awareness training for businesses across Kenya.

🔴

Digital Security Health Check

Network scan, WiFi assessment, password policy review, phishing check — with a full written report.

KSH 15,000
⏱ 1–2 days delivery
📱 Book on WhatsApp
🛡️

SME Security Audit

Full audit: email security, data protection compliance, vulnerability assessment, social engineering test + staff training.

KSH 30,000
⏱ 3–5 days delivery
📱 Book on WhatsApp
🔄

Monthly Security Retainer

Monthly scan, incident response support, staff updates, priority WhatsApp support. Peace of mind, ongoing.

KSH 10,000/month
⏱ Ongoing
📱 Book on WhatsApp
🎓

Staff Awareness Workshop

3-hour session: phishing, password hygiene, WhatsApp scams, safe browsing, Kenya Data Protection Act basics.

KSH 15,000
⏱ Half day · up to 30 staff
📱 Book on WhatsApp
🌐

Web Application Pentest

Full OWASP Top 10 assessment on your web app or API. Detailed report with CVSS ratings and remediation steps.

KSH 25,000 – 50,000
⏱ 5–7 days
📱 Book on WhatsApp
📡

IoT / Device Security Review

Hardware and firmware security assessment for connected devices. ECE-grade — your hardware, properly audited.

Custom Quote
⏱ Scope-dependent
📱 Book on WhatsApp
// Services — Tech

Tech Services

Websites, Google Business, CCTV, WiFi networks, IT support and computer repair for local businesses and homes.

🌐
Website Design

Professional 5-page business site — mobile ready, fast, SEO-optimised.

📍
Google Business

Get found on Google Maps. Setup, photos, reviews, optimisation.

📷
CCTV Setup

Camera installation, DVR/NVR config, remote viewing setup for homes and offices.

📶
WiFi Networks

Fast, secure WiFi setup for homes, shops, hotels and offices.

ServiceBook
Basic business website (5 pages)WhatsApp →
Google Business Profile setup + optimizationWhatsApp →
Domain + hosting setup + emailWhatsApp →
CCTV installation consultation + setupWhatsApp →
WiFi network setup (homes, offices)WhatsApp →
IT support retainer (monthly)WhatsApp →
Social media page setup + brandingWhatsApp →
Computer repair / maintenanceWhatsApp →
// Shop

Gear & Hardware

Pentest tools, refurbished laptops, networking gear and KnightSec merch. Ships from Kenya. M-Pesa accepted.

HOT
// PENTEST

Flipper Zero

Multi-tool for pentesters. Sub-GHz, NFC, IR, iButton, BadUSB.

KSH 28,000 – 35,000
📱 Enquire on WhatsApp
IN STOCK
// LAPTOPS

ThinkPad X/T Series (Refurb)

i5/i7 · 8–16GB RAM · 256–512GB SSD · Linux-ready · tested & cleaned.

KSH 18,000 – 45,000
📱 Enquire on WhatsApp
// PENTEST

Alfa WiFi Adapter (AWUS036ACH)

Dual-band · monitor mode · packet injection · Kali Linux compatible.

KSH 3,500 – 5,500
📱 Enquire on WhatsApp
COMING SOON
// ACCESSORIES

Raspberry Pi 4 Kits

4GB/8GB · with case, power supply, SD card preloaded with Kali/Raspbian.

KSH 7,500 – 12,000
📱 Enquire on WhatsApp
COMING SOON
// PENTEST

USB Rubber Ducky

HID attack tool · custom payload injection · Hak5 original.

KSH 4,000 – 6,000
📱 Enquire on WhatsApp
POPULAR
// NETWORKING

CCTV Camera Bundles

2MP / 4MP IP cameras · NVR kits · night vision · remote viewing.

KSH 3,500 – 15,000
📱 Enquire on WhatsApp
// NETWORKING

TP-Link Switches + PoE Gear

5/8/16 port managed & unmanaged · PoE options for CCTV and VoIP setups.

KSH 4,000 – 18,000
📱 Enquire on WhatsApp
NEW
// MERCH

KnightSec Merch

Hoodies, t-shirts, stickers, mugs — KnightSec branded. Limited drops only.

KSH 800 – 3,500
📱 Enquire on WhatsApp

M-Pesa accepted · Ships from Kenya · 7-day return policy · WhatsApp on file in Contact

// About

Who's Behind KnightSec

0xDoomsKnight
0xDoomsKnight
Penetration Tester · ECE Graduate
CJCA — March 2026CPTS — Dec 2026HTB Pro Hacker

ECE graduate turned full-time penetration tester. I build things, break things, and document both. My hardware background gives me an edge in low-level exploitation, network security and IoT/firmware pentesting — areas most security professionals don't touch.

Running KnightSec as a cybersecurity and tech services platform serving SMEs, SACCOs and schools upcountry. Archieved CJCA (March 2026) and Grinding for CPTS (December 2026). Every writeup here is real. No filler.

// Technical Skills
Network Pentesting82%
Web Application Security68%
Binary Exploitation / PWN74%
Active Directory Attacks61%
IoT / Firmware Security79%
// Certifications
🎯
CJCA
// Achieved ✓
🏆
CPTS
// In Progress — Dec 2026
⚔️
HTB Pro Hacker
// Active
🎓
ECE Graduate
// Awarded
// HTB Progress

Recent Machines

DevArea — HackTheBox Writeup (Linux, Medium)
MediumLinux
// Linux · HackTheBox
PWNED ✓🔒 Active
Kobold — HackTheBox Writeup (Linux, Easy)
EasyLinux
// Linux · HTB
PWNED ✓🔒 Active
Browsed — HackTheBox Writeup (Linux, Medium)
MediumLinux
// Linux · HTB
PWNED ✓🔒 Active
Interpreter — HackTheBox Writeup (Linux, Medium)
MediumLinux
// Linux · HTB
PWNED ✓🔒 Active
// HackTheBox
Pro Hacker
Global Rank #779 · Silver Tier
// TryHackMe
Top 3%
Rank #46565 · 108 rooms · 18 badges
// HTB Labs
35 / 521
Machines · 80 Flags · 7/819 Challenges
// HTB Sherlocks
3 / 142
Blue team investigations
// Available for Work & Enquiries

Let's Work
Together

Open to remote pentest roles, freelance security audits, tech services and product enquiries. Based in Kenya — working globally.

🔴
Security Services

Pentest, security audit, staff training, incident response.

🔵
Tech Services

Website, CCTV, WiFi, Google Business, IT support.

🟡
Shop / Products

Laptops, Flipper Zero, pentest gear, networking hardware.