$ whoami

@Lanky

Cyber Security Analyst. Bridging offensive & defensive security.

Australia · Ex-military · Structured · Methodical · Mission focused

Cyber Security Analyst working in Defence environments, focused on threat hunting, compliance, hardening, detection engineering and security control validation. My background covers NIST 800-171 and 800-53, DISA STIGs, continuous monitoring, vulnerability management, GRC and incident response support. I have completed the HTB Certified Penetration Testing Specialist (CPTS) path and am preparing for the exam to validate offensive skills and map adversary tradecraft back to stronger defensive controls.

Herd Immunity — Lanky, Cyber Security Analyst
▚ HACK THE BOX#AU
Lanky
◆ Master · Level 64 · Season 11 Silver
Master
HTB Rank
64
Level
12
Machines
#2900
S11 Rank
325
S11 Pts
10/26
S11 Flags
View live HTB profile ↗
◆ TRYHACKMEAU
LankyLuke
[0x8] Hacker · Top 15% globally
Top 15%
Rank
16
Rooms
4
Badges
View live THM profile ↗

Top Interests

ForensicsSecurity OperationsThreat Intelligence

HTB Skills

Group MembershipMisconfigurationAnalysis of Logs Network SniffingEvent Log Analysis

Toolstack & Languages

SplunkMetasploitBurp SuiteNmap PythonBashPowerShellStructured Text

Badges

Verified achievements across Credly, HTB Academy, TryHackMe and HTB Labs.

✓ Credly verified · syncing public badges

Public credentials issued and independently verifiable through Credly.

▚ HTB Academy · 53 badges
Certification & path
HTB CDSA badge
HTB Certified Defensive Security Analyst
Certified Defensive Security Analyst
The Vigilant Sentinel badge
The Vigilant Sentinel
SOC Analyst Path completed
Stand above all badge
Stand above all
Local Privilege Escalation path completed
NEWThe protector of security badge
The protector of security
Penetration Tester path completed
Offensive / Pentest modules · 30
Your first battle badge
Your first battle
Getting Started
The eye that sees all badge
The eye that sees all
Network Enum w/ Nmap
Trace before you hunt badge
You need to trace before you can hunt
Footprinting
Info is not knowledge badge
Information is not knowledge, or is it?
Info Gathering — Web
Light in the dark badge
Light in the dark
Vulnerability Assessment
Airborne delivery badge
Airborne delivery
File Transfers
Ghost in the shell badge
Ghost in the shell
Shells & Payloads
Dive into requests badge
Dive into requests
Using Web Proxies
Fuzzing is power badge
Fuzzing is power
Web Apps w/ ffuf
Crude but effective badge
Crude but effective
Login Brute Forcing
Playing with the mess badge
Playing with the mess
JavaScript Deobfuscation
Scan and execute badge
Scan and execute
Attacking Common Services
Grab the keys badge
Grab the keys and move laterally
Password Attacks
Enumerate and Attack badge
Enumerate & Attack!
AD Enumeration & Attacks
Combine the modules badge
Combine the modules
Metasploit Framework
Explore deep space badge
Explore deep space
Pivoting & Tunneling
Tactical badge
Tactical
Penetration Testing Process
Academician badge
Academician
Introduction to Academy
NEWSQL Injection Fundamentals badge
DROP your weapon
SQL Injection Fundamentals
NEWSQLMap Essentials badge
JOIN the adventure
SQLMap Essentials
NEWXSS badge
Included in every report
Cross-Site Scripting (XSS)
NEWFile Inclusion badge
Every road leads back to root
File Inclusion
NEWFile Upload Attacks badge
Prepare your payload and up you go
File Upload Attacks
NEWCommand Injections badge
Inject with caution
Command Injections
NEWArachnoid badge
Arachnoid
Web Attacks
Defensive / SOC modules · 15
NEWAll systems activated badge
All systems activated
Attacking Enterprise Networks module completed
AD Security Captain badge
AD Security Captain
Windows Attacks & Defense
Panoptic badge
Panoptic
Incident Handling Process
Anticipate the attack badge
Anticipate the next attack
Security Monitoring & SIEM
Predict the next move badge
Predict the next move
Threat Hunting w/ Elastic
Log keeper badge
Log keeper
Windows Event Logs
SPL Witchcraft badge
SPL Witchcraft
Log Sources & Splunk
Packet carver badge
Packet carver
Working with IDS/IPS
Infection detected badge
Infection detected
Intro to Malware Analysis
Lurk in the packets badge
Lurk in the packets
Network Traffic Analysis
The packet protector badge
The packet protector
Intermediate Traffic Analysis
APT slayer badge
APT slayer
Detecting Win Attacks w/ Splunk
Flare guardian badge
Flare guardian
YARA & Sigma for SOC
Chronicle champion badge
Chronicle champion
Security Incident Reporting
Code blue badge
Code blue
Intro to Digital Forensics
Milestones
Unwavering User
first weekly streak
Constant Champion
4 weekly streaks in a row
Cyber Rookie 365
1 year at HTB Academy
Binary Duo Explorer
2 years at HTB Academy
Additional Academy achievements · 5
Stairway to Heaven
HTB Academy achievement
Reach new (permission) heights
HTB Academy achievement
Attack from the outside
HTB Academy achievement
Time-consuming but important
HTB Academy achievement
Loyal Leader
HTB Academy milestone
◆ TryHackMe · 4 badges
Webbed
web fundamentals · common 23.5%
Metasploitable
Metasploit · rare 9.2%
Blue
EternalBlue · common 10.7%
Wireshark
packet analysis · rare 3.9%
▚ HTB Labs · 4 badges
Script Kiddie
Reached Script Kiddie rank
Hacker NEW
Reached Hacker rank
Is There Anybody Out There? NEW
Owned 5 machines
Just Another Brick in the Wall NEW
Owned 10 machines

Certifications

Completed credentials and active HTB certification pathways. Progress is sourced from HTB Academy.

HTB CERTIFICATIONS IN PROGRESS

HACK THE BOX · CPTS

Certified Penetration Testing Specialist

Penetration testing, web and Active Directory attack paths, privilege escalation, pivoting and professional reporting.

◷ Pending ExamPenetration Tester path · 100%view ↗
HACK THE BOX · CWES

Certified Web Exploitation Specialist

Web application penetration testing, API security, bug bounty methodology, exploitation and actionable reporting.

▸ In ProgressWeb Penetration Tester · 64.9%view ↗
HACK THE BOX · CJCA

Certified Junior Cybersecurity Associate

Hybrid offensive and defensive foundations: vulnerability assessment, exploitation, SIEM monitoring, traffic and log analysis.

▸ In ProgressJunior Cybersecurity Analyst · 30.5%view ↗
HACK THE BOX · CAPE

Certified Active Directory Pentesting Expert

Advanced Active Directory attack paths, Kerberos and NTLM abuse, ADCS, trusts, C2 and post-exploitation operations.

▸ In ProgressAD Penetration Tester · 14.2%view ↗

COMPLETED & VERIFIED

HACK THE BOX · CDSA

Certified Defensive Security Analyst

SOC operations, threat hunting, SIEM, DFIR, attack detection, malware analysis and incident reporting.

CertifiedApr 2026verify ↗
CROWDSTRIKE

Falcon 202 — Investigating & Querying Event Data with Falcon EDR

Endpoint detection and response, event querying, threat hunting and incident analysis with Falcon.

CertifiedJun 2025 · ID C342462
CLET TRAINING

Certificate IV — Security & Risk Management

CPP40707 — risk management, security operations and protective security practice.

AwardedDec 2016

MORE CERTIFICATIONS & TRAINING

MS-700 · Managing Microsoft Teams
DDLS · 2023
MS-203 · Microsoft 365 Messaging
DDLS · 2023
Cert IV · Government Security (PSP40316)
CLET · 2016
Cert IV · Government (PSP40116)
CLET · 2016
Cert III · Business Administration
CLET · 2016
Cert II · Auslan (Sign Language)
Deaf Connect · 2017
Justice of the Peace
Dept. of Justice NSW · 2017
Australian Defence Medal
Australian Army · 2016

Full list & credentials on LinkedIn ↗.

Hacking Lab

12 Hack The Box machines and 16 TryHackMe rooms completed. Write-ups and video walkthroughs are linked on each lab where available.

▚ Hack The Box — Machines

MakeSense

● Completed

Access-control gap in a custom app → file write into a root-owned path.

just completed13 Jul 2026LinuxMediumSeason 11UserRootwriteup after season

Reactor

● Completed

Next.js React Server Components RCE → root via an exposed Node.js inspector.

just completed13 Jul 2026LinuxEasySeason 11UserRootwriteup after season

Connected

● Completed

FreePBX CVE-2025-57819 → root via an incron / sysadmin signed-hook chain.

just completed13 Jul 2026LinuxEasySeason 11UserRootwriteup after season

Paperwork

● Completed

LPD command injection → PJL traversal → SSH key injection → root via a leaked privileged file descriptor.

just completed13 Jul 2026LinuxEasySeason 11UserRootwriteup after season

Bedside

● Completed

pdfminer pickle RCE → container pivot → root via a sudo-run PyTorch checkpoint.

just completed13 Jul 2026LinuxMediumSeason 11UserRootwriteup after season

Checkpoint

● Completed

AD chain: tombstone revival → VS Code extension supply-chain → patched-BadSuccessor dMSA → memory-image looting → domain admin via password reuse.

just completed25 Jul 2026WindowsMediumSeason 11UserRootwriteup after season

DarkZeroReturns

● Completed

Handlebars AST type-confusion RCE (CVE-2026-33940) → Linux-to-AD pivot across two domains → Kerberos-principal-to-root → cross-domain pass-the-hash.

just completed29 Jul 2026LinuxHardSeason 11UserRootwriteup after season

Cohort

● Completed

SSRF blocklist bypass → internal marimo pre-auth WebSocket RCE (CVE-2026-39987) → root via a held, vulnerable PackageKit package (CVE-2026-41651).

just completed2 Aug 2026LinuxEasySeason 11UserRootwriteup after season

DanglingTree

● Completed

Five-identity AD chain: WAC RCE (CVE-2026-26119) → unauth SmarterMail reset → mailbox domain-swap → SAMR reset → a dangling ADCS template (ESC1) → Domain Admin.

just completed4 Aug 2026WindowsMediumSeason 11UserRootwriteup after season

Support

● Completed

Anon SMB → decompiled binary → LDAP → RBCD → SYSTEM.

WindowsEasyUserRootread →

CCTV

● Completed

Default creds → creds in shell history → forged auth signature.

LinuxEasyUserRootread →

Nexus

● Completed

Retired · Linux.

LinuxEasyUserRootwriteup soon

◆ TryHackMe — Rooms

Documented · writeup + video

Also completed

Vulnversity
Easy · Web
Game Zone
Easy · SQLi
Steel Mountain
Easy · Windows
Alfred
Easy · Jenkins
OWASP Juice Shop
Easy · Web
Network Services
Easy · Networking
Network Services 2
Easy · Networking
Introductory Networking
Easy · Networking
What the Shell?
Easy · Shells
Wireshark 101
Easy · Traffic
Nessus
Easy · Vuln Scan
Sakura Room
Easy · OSINT

▶ Technique & Tutorial Videos

Non-lab-specific demos from my channel, Lanky's Networking.

Projects

Systems I have designed, built and run, from security tooling to infrastructure.

Under construction

A self-hosted threat-intelligence dashboard that tracks security events as they break. It aggregates new CVEs, data-breach reports, threat-actor activity and general infosec news alongside social feeds from Mastodon, Bluesky and Reddit into a single continuously updating board.

I built it to stay current with emerging threats and to feed that context into my defensive work: threat hunting, vulnerability management and detection engineering.

CVE / Vuln tracking Data breaches Threat actors RSS / social aggregation Self-hosted Threat intel
▸ Open Cyber Deck ↗ ▸ Full details
Splunk and Tenable Vulnerability Dashboard
Self-hosted SIEM · vulnerability management
Just gone Live

A Splunk Enterprise deployment that ingests Tenable vulnerability and hardening scan data and turns it into an operational security picture. The dashboard gives an OS-filtered drill-down, per-host compliance trends and high-risk finding tracking across a rolling twelve months.

It follows the same workflow as a production vulnerability-management programme: export findings from Tenable, index them in Splunk, then report on remediation progress and hardening posture.

Splunk Enterprise Tenable / Nessus Vulnerability management SIEM dashboards SPL Compliance trending Docker
▸ Full details
Family-Safe Internet Filtering
Pi-hole · WireGuard · Cloudflare for Families
Under construction

Giving my child's device the same filtered internet at home and away. On the home network, a Pi-hole with a family-safe upstream resolver blocks ads, trackers, malware and adult content for every device. Off the network, an always-on WireGuard tunnel routes the device back home so it keeps the same protection on mobile data.

Step 1 is complete: a self-healing route home, combining a WireGuard server with an automated dynamic-DNS updater so the tunnel survives the ISP changing our public IP.

Pi-hole DNS filtering WireGuard VPN Cloudflare for Families Dynamic DNS Parental controls Defense-in-depth
▸ Full details
Autonomous Agent Operations Team
Self-hosted · LLM automation
● Live

A multi-agent system that monitors and self-heals my home lab around the clock. Eight specialist agents cover security, DNS, networking, containers, backups, updates, media and storage, each on its own schedule under a supervising manager agent, with a WhatsApp service desk for alerts and requests.

They run health checks, catch configuration drift, remediate common failures automatically and log every change. The structure mirrors a real L1 to L3 IT support model.

Multi-agent LLMs SecOps / AIOps Self-healing infra Scheduled automation WhatsApp bot Linux / SSH
▸ Full details
Self-Hosted Home Lab
Ubuntu · Docker · 35+ containers
● Live

A self-hosted server running over 35 Docker containers across a dozen compose stacks on Ubuntu. It sits behind Nginx Proxy Manager for TLS, uses Cloudflare Tunnels so no inbound ports are open, provides WireGuard for remote access, and runs Pi-hole for network-wide DNS filtering.

This is where I get hands-on with Linux administration, containerisation, networking and defensive hardening: reverse proxies, segmentation, secrets handling, NAS backups and monitoring.

Docker / Compose Nginx Proxy Manager Cloudflare Tunnels WireGuard VPN Pi-hole DNS Ubuntu Linux Backups / NAS
▸ Full details
Private LLM Stack
Ollama · Open WebUI
● Live

A self-hosted AI stack running Ollama on a GPU with Open WebUI as the front end. No data leaves the network, which makes it a private environment for running models, testing prompts and providing inference to the automation behind my agent team.

Ollama Open WebUI Local LLMs GPU inference Data privacy
▸ Full details
Home Assistant Smart Home
Home Assistant · Matter · Zigbee
● Live

A locally controlled smart-home platform built on Home Assistant, bridging Matter, Zigbee and MQTT devices through a Mosquitto broker. Automations, dashboards and app control all stay on the network rather than depending on vendor clouds.

Home Assistant Matter Zigbee2MQTT MQTT / Mosquitto IoT automation
▸ Full details
Jellyfin Media Server
Jellyfin · Jellyseerr
● Live

A self-hosted media streaming platform built on Jellyfin. My own library is transcoded on the GPU and streamed to any device on the network, with Jellyseerr providing a request front end for the household. It replaces a commercial streaming subscription and runs entirely on my own hardware.

Jellyfin Jellyseerr GPU transcoding Self-hosted Container networking
▸ Full details
Australian Homestead
australianhomestead.com ↗
● Live

A self-hosted WordPress site on a containerised stack: WordPress on PHP 8.3 behind an Nginx front end with a MariaDB backend. It is deployed with Docker Compose and published through the same reverse proxy and tunnel setup as the rest of the lab.

WordPress Nginx MariaDB PHP 8.3 Docker Compose
▸ Visit australianhomestead.com ↗ ▸ Full details
● Live

The site you are reading: a hand-built static portfolio with no dependencies or build step, hosted on GitHub Pages. It documents my Hack The Box and TryHackMe machines, HTB Academy progress, certifications and video walkthroughs.

Static HTML / CSS / JS GitHub Pages Zero build
⌥ GitHub

Automation & Scripts

43 scripts that run my home lab, covering security scanning, self-healing, an autonomous agent framework and general operations. Click a linked script name to read its sanitised source. These are the real running scripts, with secrets such as tokens, IDs and phone numbers replaced by placeholders.

When to use the scripts

Purpose: this section is the quick-training reference for people and AI agents: what each script is for, the best time to use it, who must approve it, and what verification follows. The live server catalogue is execution authority; a filename is never permission to run it.

Every morning
Review the latest system, admin, NAS and Docker status reports. Run a fresh approved health check when the report is stale, missing, or Luke asks for one.
When an issue is noticed
Start with the narrowest read-only health/status script for the affected service. Capture evidence under one ticket before considering a restart or repair.
Continuously (managed services only)
Alert monitors, Telegram routing, DDNS and ARR synchronisation run through their existing services/timers. Agents inspect their status and logs; they do not launch duplicate daemons or pollers.
Saturday night maintenance window
With Luke's approval: take the Docker configuration backup, run run-tonight-updates.sh to sequence OS and container updates, then perform a fresh health check and review failures or reboot requirements.
Weekly / monthly review
Review hardening, suspicious-login, storage-capacity, duplicate and media-quality reports. Broad AV/CVE scans should run in an approved low-impact window; cleanup remains a separate owner-approved action.
Incident or change only
Watchdogs, mount repair, device repair, notifications, OAuth setup, recycling, cleanup and update scripts are approval-gated. Internal router, handoff, sandbox and manager scripts are called only by their managed workflow.

Security & hardening 9

Blue-team automation: scanning, auditing and fail-safe controls.

Hardening audit that walks SSH config, sudo, firewall and kernel settings and prints a [PASS]/[FAIL] per control.
Runs Trivy against every running Docker image to surface known CVEs: report-only, against live vulnerability databases.
Scoped ClamAV malware scans (quick / docker-config / nas-media / home) with single-instance locking.
Reads the auth journal for SSH brute-force candidates and other suspicious activity, producing a windowed security report.
Packages the cyber agent's findings into a structured handoff for escalation.
Delivers security alerts out to the notification channel.
Host admin snapshot: uptime, sessions and posture checks for a quick "is everything sane" read.
A sandbox wrapper that constrains which commands the autonomous agents are allowed to execute.
Fail-safe deletion: moves files to a @Recycle area with a JSON audit trail instead of ever hard-deleting.

AI agent framework 6

The orchestration layer behind the agent ops team.

The L2 watchdog: performance review, gap analysis and job-description enforcement across the whole agent fleet.
Natural-language router that maps a chat phrase ("check jellyfin") to the correct approved action or script.
Routes incoming tickets/requests to the agent that owns that domain.
Structured handoff of work and context between agents.
Encodes the issues only a human (L3) can decide, including the affected system, the reasoning and the proposed change.
The L2 Docker agent's logic. Use status only for a full inventory; use problems when asked which containers are stopped/unhealthy and why. Restart remains approval-gated.

Monitoring & self-healing 8

Detect → remediate → report, delivered to my phone.

Full server healthcheck (v2): services, mounts, containers, disk and GPU in one pass.
Detects stale NAS/CIFS mounts, stops affected containers, remounts, and only restarts once storage is readable again.
Watches for alert conditions and fires notifications when thresholds trip.
Runs a health check and delivers the result to WhatsApp.
Pushes a full health summary to the WhatsApp channel.
Sends only verified health results: guards against false-positive "all good" messages.
Rewrites raw technical output into a plain-English report a human actually wants to read.
Test harness for the WhatsApp health-agent pipeline.

Storage & NAS 7

Keeping a 21 TB NAS healthy and tidy.

NAS capacity check with threshold warnings.
Overall NAS health & availability report.
Finds and reports duplicate files across the NAS.
Removes duplicates safely (via safe-recycle, never a hard delete).
Clears junk / temp / leftover files to reclaim space.
Audits the media library for integrity and metadata issues.
Generates a review of the media library for the media agent.

Media library 3

Quality checks for the Jellyfin library.

Flags media with missing or non-English audio/subtitle tracks.
arr-rss-sync.pypython
Managed ARR synchronisation job. Use through its scheduled service; inspect logs rather than launching a second run from chat.
arr-rejected-download-cleanup.pypython
Cleans rejected download records. Run only after Media Manager review and Luke's approval because it changes records.

Backups & updates 4

Reproducibility and staying patched.

Archives every stack's compose + .env files to the NAS with retention: the "rebuild from scratch" safety net.
Pulls and recreates Docker stacks. Use only in the approved Saturday-night window or an approved urgent patch.
Applies host OS updates. Use only in the approved Saturday-night window or for an approved urgent security patch.
Owner-approved Saturday-night runner that sequences OS and image updates; verify health and reboot requirements afterwards.

Notifications & bots 3

How the lab talks back to me.

Unified Telegram channel for the agent team: a second control/notification surface alongside WhatsApp.
Central dispatcher for admin notifications.
One-time Google OAuth setup granting Gmail + Calendar access for the assistant.

Infrastructure utilities 3

Small fixers that keep the plumbing working.

Ensures the media containers mount the shared storage path correctly after config changes.
Recovers Govee lighting by running a repair routine inside the Home Assistant container.
cloudflare-ddns.pypython
Managed DDNS updater. Use through its scheduled service when the public address changes; agents inspect status and logs rather than running it manually.

Presentations

Talks, demos and slide decks — explaining security work to both technical and non-technical audiences.

More on the way More talks — conference, community and internal sessions — will be added here as slide decks and recordings become available.