Certifications & Training
Status overview #
| Status | Programs |
|---|---|
| Completed certifications and training | 8 |
| Currently in progress | 2 |
| Planned advanced training | 1 |
Completed certifications #
The following certifications and training programs have been successfully completed.
Offensive Security #
OSCE³ - Offensive Security Certified Expert 3 #
Completed OffSec Advanced
The OSCE³ designation is awarded after earning all three OffSec 300-level certifications:
- OSED - Offensive Security Exploit Developer
- OSEP - Offensive Security Experienced Penetration Tester
- OSWE - Offensive Security Web Expert
Core skills: exploit development, evasive tradecraft, advanced penetration testing, source-code review, and web application exploitation.
Verify OSCE³ credentialOSED - Offensive Security Exploit Developer #
Completed Exploit Development Windows
Advanced Windows exploit-development training focused on analyzing and exploiting memory-corruption vulnerabilities.
Core skills:
- Windows exploit development
- x86 assembly
- Stack-based memory corruption
- DEP and ASLR bypasses
- Return-oriented programming
- Shellcode development
- Reverse engineering
- WinDbg automation
Many of the exploit-development and Windows-internals articles published on PentestHacks were influenced by skills developed during this training.
Verify OSED credentialOSEP - Offensive Security Experienced Penetration Tester #
Completed Penetration Testing Red Team
Advanced penetration-testing training covering enterprise environments, Active Directory, defensive bypasses, and evasive tradecraft.
Core skills:
- Advanced penetration testing
- Active Directory attacks
- Network-filtering bypasses
- Application allow-listing bypasses
- Lateral movement
- Credential access
- Evasion techniques
- Offensive PowerShell and C#
OSWE - Offensive Security Web Expert #
Completed Web Security Source Review
White-box web application security training focused on discovering and exploiting vulnerabilities through source-code analysis.
Core skills:
- White-box web application testing
- Source-code review
- Authentication bypasses
- Injection vulnerabilities
- Insecure deserialization
- Server-side attacks
- Exploit development and automation
OSCP - Offensive Security Certified Professional #
Completed Penetration Testing
Practical penetration-testing certification that established my foundation in offensive security.
Core skills:
- Network enumeration
- Vulnerability discovery
- Exploitation
- Linux and Windows privilege escalation
- Active Directory fundamentals
- Technical reporting
Red Teaming #
HTB APTLabs - Red Team Operator Level III #
Completed Red Team Active Directory
Practical red-team and adversary-simulation training conducted in complex enterprise environments.
Core skills:
- Active Directory exploitation
- Enterprise attack paths
- Credential abuse
- Trust-relationship attacks
- Lateral movement
- Post-exploitation
- Operational planning
Malware Development and Reverse Engineering #
MalDev Academy Certified #
Completed Malware Development Windows Internals
Training focused on Windows malware-development concepts and the internal mechanisms used by offensive tooling.
Core skills:
- Windows API programming
- Process injection
- Payload execution
- API hashing
- Evasion concepts
- Windows internals
- C and C++ development
IMBT - Introduction to Malware Binary Triage #
Completed InvokeRE Reverse Engineering
Practical malware binary-triage and reverse-engineering training completed through InvokeRE.
Core skills:
- Static malware analysis
- Dynamic malware analysis
- Binary triage
- Reverse engineering
- Windows API analysis
- Malware capability identification
- IDA and Binary Ninja Version
- Technical analysis reporting
Malware Analyst Professional - Level 1 #
Completed TrainSec Malware Analysis
Foundational malware-analysis certification covering investigation methodology and technical reporting.
Core skills:
- Static analysis
- Dynamic analysis
- Behavioral investigation
- Indicators of compromise
- Malware reporting
Current training #
These programs are actively in progress and are not presented as completed certifications.
AMBT - Advanced Malware Binary Triage, Binary Ninja Edition #
In Progress InvokeRE Binary Ninja
Advanced malware-analysis training using Binary Ninja.
Current focus:
- Advanced static analysis
- Binary Ninja workflows
- Malware capability identification
- Reverse-engineering methodology
- Analyst automation
- Technical reporting
CRTO - Certified Red Team Operator #
Exam Preparation Red Team Active Directory
The course material has been completed, and preparation for the practical examination is ongoing.
Current focus:
- Command-and-control operations
- Active Directory tradecraft
- Kerberos attacks
- Credential access
- Lateral movement
- Privilege escalation
- Operational security
- Adversary emulation
Planned training #
The following program is part of my longer-term development plan and should not be interpreted as completed or currently active training.
Zero2Automated - Advanced Malware Analysis #
Planned Malware Analysis Automation
The course has been purchased and is planned after completing AMBT and the CRTO examination.
Planned areas of study:
- Real-world malware analysis
- Malware loaders
- Unpacking
- Process injection
- Shellcode analysis
- Anti-analysis techniques
- Persistence
- Malware configuration extraction
- Python-based analyst automation
- YARA development
- Malware-family research
Research roadmap #
My continued technical development includes:
- Malware reverse engineering
- Binary Ninja and Ghidra
- Windows internals
- Exploit development
- Heap exploitation
- Vulnerability research
- Red-team operations
- AI-assisted reverse engineering
- Private RAG and MCP-assisted research workflows
Certifications represent completed milestones. Continued experimentation, research, and practical application are what turn those milestones into lasting expertise.