Skills & ExpertiseBacarıqlar və İxtisas

Practical, hands-on skills across network, web application, and Active Directory environments — from reconnaissance to post-exploitation.

Şəbəkə, veb tətbiq və Active Directory mühitlərində reconnaissance-dan post-exploitation-a qədər praktiki iş və təhlil bacarıqları.

01 Penetration Testing & Infrastructure

  • Experienced in penetration testing across enterprise networks, systems, and endpoints.
  • Skilled in reconnaissance, exploitation, and post-exploitation using tools such as Nmap, Metasploit, Cobalt Strike, and Havoc C2.
  • Proficient in vulnerability assessment, reporting, and remediation verification.
  • Skilled in credential harvesting and offline password attacks using John the Ripper and Hashcat.
  • Korporativ şəbəkələr, sistemlər və son nöqtələr üzrə penetration testing təcrübəsi.
  • Nmap, Metasploit, Cobalt Strike və Havoc C2 vasitəsilə kəşfiyyat, istismar (exploitation) və post-exploitation mərhələlərində bacarıq.
  • Zəifliklərin qiymətləndirilməsi, hesabat yazılışı və düzəlişlərin doğrulanması (remediation verification).
  • John the Ripper və Hashcat ilə oflayn parol hücumları (password cracking & hash analysis).
Nmap Metasploit Cobalt Strike Havoc C2 John the Ripper Hashcat

02 Web Application Security

  • Strong knowledge of OWASP Top 10 vulnerabilities, including XSS, SQL Injection, CSRF, RCE, LFI/RFI, IDOR, and directory traversal.
  • Experienced in web application security assessments using Burp Suite Pro, SQLmap, and customized manual testing methodologies.
  • Skilled in identifying complex business logic flaws, authorization bypasses, and API vulnerabilities.
  • OWASP Top 10 zəiflikləri üzrə dərin bilik: XSS, SQL Injection, CSRF, RCE, LFI/RFI, IDOR və directory traversal.
  • Burp Suite Pro, SQLmap və xüsusi manual test metodologiyaları ilə veb tətbiq təhlükəsizliyinin yoxlanılması.
  • Mürəkkəb biznes məntiqli xətaların (logic flaws), səlahiyyət aşmalarının (IDOR) və API zəifliklərinin aşkarlanması.
Burp Suite Pro SQLmap OWASP Top 10 XSS SQLi IDOR API Security

03 Active Directory Exploitation

  • Perform AD enumeration, domain mapping, and attack path discovery using BloodHound, PowerView, and SharpHound.
  • Exploit common AD misconfigurations: Kerberoasting, AS-REP Roasting, Pass-the-Ticket, and Unconstrained Delegation.
  • Map and execute lateral movement and domain privilege escalation paths in simulated enterprise environments.
  • BloodHound, PowerView və SharpHound istifadə etməklə AD enumeration, domen xəritələndirilməsi və hücum yollarının aşkarlanması.
  • AD konfiqurasiya boşluqlarının istismarı: Kerberoasting, AS-REP Roasting, Pass-the-Ticket və Unconstrained Delegation.
  • Korporativ mühitlərdə lateral movement (yanal keçidlər) və domen səviyyəsində səlahiyyət artımı (privilege escalation) yollarının icrası.
BloodHound PowerView SharpHound Kerberoasting AS-REP Roasting Pass-the-Ticket