◂ IDAN.LAB // SECURITY NOTES
// whoami

Hi, I'm Idan.

A 26-year-old cybersecurity enthusiast who fell hard for offensive security and never looked back. This site is my lab notebook made public, a growing collection of machine walkthroughs, CTF solutions, and the things I learn breaking (and understanding) systems.

// Philosophy

How I approach things

Every machine I solve follows the same loop: recon, foothold, escalation, reflection. The writeups here aren't just "type these commands." They document my actual thought process, the dead ends, and what each box taught me.

I don't just want to know what the exploit is. I want to know why it works, what the defender missed, and how I'd catch it next time.

If a so-called "easy" box humbled me, I'll say so. That's how you actually get better.

// Capabilities

What I work with

Web Security

SQL injection, XSS, authentication flaws, and the logic bugs that hide in plain sight.

Reverse Engineering

Binary analysis, understanding what a program really does beneath the surface.

Privilege Escalation

Linux and Windows privesc: misconfigurations, relative paths, and overlooked permissions.

OSINT & Recon

Mapping an attack surface before touching it. Information is the first foothold.

Cryptography

Breaking weak implementations and understanding the math that protects (or fails) us.

Tooling & Scripting

Kali Linux daily-driver, Python and Bash for automating the boring parts.

// Proving Grounds

Where I practice

Everything here happens in legal, controlled environments: CTF competitions, intentionally vulnerable labs, and personal VMs.

HackTheBoxRetired machines, full methodology breakdowns.
VulnHubOffline vulnerable VMs in my home lab.
PicoCTFWhere I built my CTF fundamentals.
OverTheWireWargames that taught me more Linux than any course.
// Trajectory

Where I'm headed

I'm actively sharpening my skills toward my first role in security: pentesting, red teaming, or anywhere I get to break things for the right reasons.

I learn fast, I document everything, and I genuinely love this work.

// Contact

Let's connect.

Hiring, collaborating, or just want to talk shop? My inbox is open, and so is my code. I'm always happy to meet others in the field.

GitHub